7.3

CVSS3.1

CVE-2024-10174 - WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt cha…

The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.6.13 via the 'Abstract_Permission' class due to missing validation on the 'user_i…

📅 Published: Nov. 13, 2024, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:28 p.m.

9.8

CVSS3.1

CVE-2024-10820 - WooCommerce Upload Files <= 84.3 - Unauthenticated Arbitrary File Upload

The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 84.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sit…

📅 Published: Nov. 13, 2024, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:17 p.m.

8.1

CVSS3.1

CVE-2024-10828 - Advanced Order Export For WooCommerce <= 3.5.5 - Unauthenticated PHP Object Injection via Order Det…

The Advanced Order Export For WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.5.5 via deserialization of untrusted input during Order export when the "Try to convert serialized values" option is enabled. This makes it possible for unaut…

📅 Published: Nov. 13, 2024, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 5:12 p.m.

4.3

CVSS3.1

CVE-2024-10794 - Boostify Header Footer Builder for Elementor <= 1.3.6 - Authenticated (Contributor+) Post Disclosure

The Boostify Header Footer Builder for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.6 via the 'bhf' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with C…

📅 Published: Nov. 13, 2024, 3:20 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-10802 - Hash Elements <= 1.4.7 - Missing Authorization to Unauthenticated Draft Post Title Exposure

The Hash Elements plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the hash_elements_get_posts_title_by_id() function in all versions up to, and including, 1.4.7. This makes it possible for unauthenticated attackers to retrieve draft post titles…

📅 Published: Nov. 13, 2024, 3:20 a.m. 🔄 Last Modified: April 8, 2026, 4:32 p.m.

5.3

CVSS3.1

CVE-2024-10529 - Kognetiks Chatbot for WordPress <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Ass…

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level acc…

📅 Published: Nov. 13, 2024, 2:33 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

4.3

CVSS3.1

CVE-2024-11143 - Kognetiks Chatbot for WordPress <= 2.1.8 - Cross-Site Request Forgery to Authenticated (Subscriber+…

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due to missing or incorrect nonce validation on the update_assistant, add_new_assistant, and delete_assistant functions. This makes it possible f…

📅 Published: Nov. 13, 2024, 2:33 a.m. 🔄 Last Modified: April 8, 2026, 5:32 p.m.

6.1

CVSS3.1

CVE-2024-10684 - Kognetiks Chatbot for WordPress <= 2.1.7 - Reflected Cross-Site Scripting

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arb…

📅 Published: Nov. 13, 2024, 2:33 a.m. 🔄 Last Modified: April 8, 2026, 5:26 p.m.

5.3

CVSS3.1

CVE-2024-10531 - Kognetiks Chatbot for WordPress <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Ass…

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level acc…

📅 Published: Nov. 13, 2024, 2:33 a.m. 🔄 Last Modified: April 8, 2026, 5:23 p.m.

4.3

CVSS3.1

CVE-2024-10530 - Kognetiks Chatbot for WordPress <= 2.1.7 - Missing Authorization to Authenticated (Subscriber+) Ass…

The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function in all versions up to, and including, 2.1.7. This makes it possible for authenticated attackers, with subscriber-level ac…

📅 Published: Nov. 13, 2024, 2:33 a.m. 🔄 Last Modified: April 8, 2026, 5:13 p.m.
Total resulsts: 349182
Page 7902 of 34,919
« previous page » next page
Filters