4.3

CVSS3.1

CVE-2024-10669 - Countdown Timer block – Display the event's date into a timer. <= 1.2.4 - Authenticated (Contributo…

The Countdown Timer block – Display the event&#039;s date into a timer. plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.4 via the [ctb] shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenti…

📅 Published: Nov. 9, 2024, 4:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-10814 - Code Embed <= 2.5 - Authenticated (Contributor+) Server-Side Request Forgery

The Code Embed plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.5 via the ce_get_file() function. This makes it possible for authenticated attackers, with contributor-level access and above, to make web requests to arbitrary locations origina…

📅 Published: Nov. 9, 2024, 4:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-10770 - Envo Extra <= 1.9.3 - Authenticated (Contributor+) Post Disclosure

The Envo Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.9.3 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level ac…

📅 Published: Nov. 9, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 4:34 p.m.

4.3

CVSS3.1

CVE-2024-10693 - SKT Addons for Elementor <= 3.3 - Authenticated (Contributor+) Post Disclosure

The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.3 via the Unfold widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access …

📅 Published: Nov. 9, 2024, 3:30 a.m. 🔄 Last Modified: April 8, 2026, 5:05 p.m.

9.8

CVSS3.1

CVE-2024-10627 - WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Upload

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to upload arbitrary…

📅 Published: Nov. 9, 2024, 3:30 a.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

8.8

CVSS3.1

CVE-2024-10626 - WooCommerce Support Ticket System <= 17.7 - Authenticated (Subscriber+) Arbitrary File Deletion

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for authenticated attackers, with Subscriber-level a…

📅 Published: Nov. 9, 2024, 3:18 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

9.8

CVSS3.1

CVE-2024-10625 - WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Deletion

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to delete arbitrar…

📅 Published: Nov. 9, 2024, 3:18 a.m. 🔄 Last Modified: April 8, 2026, 5:28 p.m.

8.8

CVSS3.1

CVE-2024-10674 - Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Sub…

📅 Published: Nov. 9, 2024, 3:18 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9226 - Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.6 - Reflected Cross-Si…

The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.7.6. This makes it possible for unauthentica…

📅 Published: Nov. 9, 2024, 3:18 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-10673 - Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-…

📅 Published: Nov. 9, 2024, 3:17 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 7970 of 34,919
« previous page » next page
Filters