8.5

CVSS3.1

CVE-2024-52495 - WordPress Distance Based Shipping Calculator plugin <= 2.0.23 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in enituretechnology Distance Based Shipping Calculator distance-based-shipping-calculator allows SQL Injection.This issue affects Distance Based Shipping Calculator: from n/a through <= 2.0.23.

πŸ“… Published: Nov. 28, 2024, 10:43 a.m. πŸ”„ Last Modified: April 23, 2026, 3:21 p.m.

10

CVSS3.1

CVE-2024-52490 - WordPress Pathomation plugin <= 2.5.1 - Arbitrary File Upload vulnerability

Unrestricted Upload of File with Dangerous Type vulnerability in pathomation Pathomation pathomation allows Upload a Web Shell to a Web Server.This issue affects Pathomation: from n/a through <= 2.5.1.

πŸ“… Published: Nov. 28, 2024, 10:42 a.m. πŸ”„ Last Modified: April 23, 2026, 3:21 p.m.

7.5

CVSS3.1

CVE-2024-52496 - WordPress Absolute Addons For Elementor plugin <= 1.0.14 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AbsolutePlugins Absolute Addons For Elementor absolute-addons allows Local Code Inclusion.This issue affects Absolute Addons For Elementor: from n/a through <= 1.0.14.

πŸ“… Published: Nov. 28, 2024, 10:41 a.m. πŸ”„ Last Modified: April 23, 2026, 3:21 p.m.

7.5

CVSS3.1

CVE-2024-52497 - WordPress Shopready plugin <= 3.6 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in quomodosoft Shopready shopready-elementor-addon allows PHP Local File Inclusion.This issue affects Shopready: from n/a through <= 3.6.

πŸ“… Published: Nov. 28, 2024, 10:39 a.m. πŸ”„ Last Modified: April 23, 2026, 3:21 p.m.

7.5

CVSS3.1

CVE-2024-52498 - WordPress SP Blog Designer plugin <= 1.0.0 - Local File Inclusion vulnerability

Path Traversal: '.../...//' vulnerability in softpulseinfotech SP Blog Designer sp-blog-designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through <= 1.0.0.

πŸ“… Published: Nov. 28, 2024, 10:38 a.m. πŸ”„ Last Modified: April 23, 2026, 3:21 p.m.

7.5

CVSS3.1

CVE-2024-52499 - WordPress Pricing table addon for elementor plugin <= 1.0.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ibrahim Pricing table addon for elementor pricing-table-addon-for-elementor allows PHP Local File Inclusion.This issue affects Pricing table addon for elementor: from n/a through…

πŸ“… Published: Nov. 28, 2024, 10:38 a.m. πŸ”„ Last Modified: April 23, 2026, 3:21 p.m.

7.5

CVSS3.1

CVE-2024-52501 - WordPress Office Locator plugin <= 1.3.0 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebbyTemplate Office Locator office-locator.This issue affects Office Locator: from n/a through <= 1.3.0.

πŸ“… Published: Nov. 28, 2024, 10:37 a.m. πŸ”„ Last Modified: April 23, 2026, 3:21 p.m.

7.5

CVSS3.1

CVE-2024-52481 - WordPress Jobify theme < 4.3.0 - Unauthenticated Arbitrary File Read vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify jobify allows Relative Path Traversal.This issue affects Jobify: from n/a through < 4.3.0.

πŸ“… Published: Nov. 28, 2024, 10:35 a.m. πŸ”„ Last Modified: April 1, 2026, 4:20 p.m.

0.0

CVE-2024-11620 - WordPress Rank Math SEO plugin <= 1.0.231 - Arbitrary .htaccess Overwrite to Remote Code Execution …

Improper Control of Generation of Code ('Code Injection') vulnerability in Rank Math SEO Rank Math SEO seo-by-rank-math allows Code Injection.This issue affects Rank Math SEO: from n/a through <= 1.0.231.

πŸ“… Published: Nov. 28, 2024, 10:34 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-52475 - WordPress Wawp plugin < 3.0.18 - Account Takeover vulnerability

Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-platform allows Authentication Bypass.This issue affects Wawp: from n/a through < 3.0.18.

πŸ“… Published: Nov. 28, 2024, 10:34 a.m. πŸ”„ Last Modified: April 23, 2026, 3:21 p.m.
Total resulsts: 349182
Page 7678 of 34,919
Β« previous page Β» next page
Filters