6.1

CVSS3.1

CVE-2024-10850 - Razorpay Payment Button for Elementor <= 1.2.5 - Reflected Cross-Site Scripting

The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5. This makes it possible for unauthenticated attack…

📅 Published: Nov. 13, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.1

CVSS3.1

CVE-2024-9614 - Constant Contact Forms by MailMunch <= 2.1.2 - Reflected Cross-Site Scripting

The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.1.2. This makes it possible for unauthenticated attackers to inject arbitrary …

📅 Published: Nov. 13, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

6.1

CVSS3.1

CVE-2024-10577 - Fat Rat Collect <= 2.7.3 - Reflected Cross-Site Scripting

The 胖鼠采集(Fat Rat Collect) 微信知乎简书腾讯新闻列表分页采集, 还有自动采集、自动发布、自动标签、等多项功能。开源插件 plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing escaping on a URL in all versions up to, and including, 2.7.3. This makes it possible for unauthenticated attackers to inject arbitrary web scr…

📅 Published: Nov. 13, 2024, 2:02 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-10887 - NiceJob <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The NiceJob plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes (nicejob-lead, nicejob-review, nicejob-engage, nicejob-badge, nicejob-stories) in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping …

📅 Published: Nov. 13, 2024, 2:02 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-10851 - Razorpay Payment Button <= 2.4.6 - Reflected Cross-Site Scripting

The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.6. This makes it possible for unauthenticated attackers to inj…

📅 Published: Nov. 13, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-8985 - Social Proof (Testimonials) Slider <= 2.2.4 - Authenticated (Contributor+) Stored Cross-Site Script…

The Social Proof (Testimonial) Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spslider-block shortcode in all versions up to, and including, 2.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl…

📅 Published: Nov. 13, 2024, 2:02 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-9578 - Hide Links <= 1.4.2 - Unauthenticated Shortcode Execution

The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available on the tar…

📅 Published: Nov. 13, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.

4.3

CVSS3.1

CVE-2024-10852 - Buy one click WooCommerce <= 2.2.9 - Missing Authorization to Authenticated (Subscriber+) Settings …

The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX action in all versions up to, and including, 2.2.9. This makes it possible for authenticated attackers, with Subscriber-level ac…

📅 Published: Nov. 13, 2024, 2:02 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-10778 - BuddyPress Builder for Elementor – BuddyBuilder <= 1.7.4 - Authenticated (Contributor+) Post Disclo…

The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.4 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated…

📅 Published: Nov. 13, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 5:17 p.m.

7.2

CVSS3.1

CVE-2024-38655 -

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

📅 Published: Nov. 13, 2024, 1:54 a.m. 🔄 Last Modified: June 27, 2025, 6:43 p.m.
Total resulsts: 349182
Page 7904 of 34,919
« previous page » next page
Filters