6.4

CVSS3.1

CVE-2024-11431 - Ragic Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-8066 - File Manager Pro – Filester <= 1.8.6- Authenticated (Subscriber+) Arbitrary File Upload

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted p…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

6.4

CVSS3.1

CVE-2024-11203 - EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audi…

The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘provider_name parameter in all versions up to, and including, 4.1.3 due to…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

6.4

CVSS3.1

CVE-2024-11788 - StreamWeasels YouTube Integration <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11761 - LegalWeb Cloud <= 1.1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The LegalWeb Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'legalweb-popup' shortcode in all versions up to, and including, 1.1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-36466 - Unauthenticated Zabbix frontend takeover when SSO is being used

A bug in the code allows an attacker to sign a forged zbx_session cookie, which then allows them to sign in with admin permissions.

📅 Published: Nov. 28, 2024, 7:19 a.m. 🔄 Last Modified: Oct. 8, 2025, 3:31 p.m.

9.8

CVSS3.1

CVE-2024-11925 - WP JobSearch <= 2.6.7 - Authentication Bypass to Account Takeover and Privilege Escalation

The JobSearch WP Job Board plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 2.6.7. This is due to the plugin not properly verifying a users identity when verifying an email address through the user_account_activation function. This makes it possible f…

📅 Published: Nov. 28, 2024, 7:14 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.4

CVSS3.1

CVE-2024-10896 - Logo Slider < 4.5.0 - Contributor+ Stored XSS

The Logo Slider WordPress plugin before 4.5.0 does not sanitise and escape some of its Logo and Slider settings, which could allow high privilege users such as Contributor to perform Stored Cross-Site Scripting

📅 Published: Nov. 28, 2024, 6 a.m. 🔄 Last Modified: May 15, 2025, 5:35 p.m.

4.8

CVSS3.1

CVE-2024-10510 - adBuddy+ (AdBlocker Detection) by NetfunkDesign <= 1.1.3 - Admin+ Stored XSS

The adBuddy+ (AdBlocker Detection) by NetfunkDesign WordPress plugin through 1.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for examp…

📅 Published: Nov. 28, 2024, 6 a.m. 🔄 Last Modified: June 9, 2025, 9:17 p.m.

5.4

CVSS3.1

CVE-2024-10493 - Element Pack Elementor Addons < 5.10.3 - Contributor+ Stored XSS

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) WordPress plugin before 5.10.3 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the con…

📅 Published: Nov. 28, 2024, 6 a.m. 🔄 Last Modified: May 15, 2025, 5:37 p.m.
Total resulsts: 349182
Page 7681 of 34,919
« previous page » next page
Filters