6.5

CVSS3.1

CVE-2024-49665 - WordPress Web Bricks Addons for Elementor plugin <= 1.1.1 - Stored Cross Site Scripting (XSS) vuln…

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Web Bricks Web Bricks Addons for Elementor allows Stored XSS.This issue affects Web Bricks Addons for Elementor: from n/a through 1.1.1.

πŸ“… Published: Oct. 29, 2024, 11:20 a.m. πŸ”„ Last Modified: April 28, 2026, 4:10 p.m.

6.5

CVSS3.1

CVE-2024-49667 - WordPress Local Business Addons For Elementor plugin <= 1.1.5 - Stored Cross Site Scripting (XSS) v…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Asaduzzaman Abir Local Business Addons For Elementor map-addons-for-elementor-waze-map allows Stored XSS.This issue affects Local Business Addons For Elementor: from n/a through <= 1.1.5.

πŸ“… Published: Oct. 29, 2024, 11:11 a.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

7.1

CVSS3.1

CVE-2024-49670 - WordPress Client Power Tools Portal plugin <= 1.9.0 - Reflected Cross Site Scripting (XSS) vulnerab…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sam Glover Client Power Tools Portal client-power-tools allows Reflected XSS.This issue affects Client Power Tools Portal: from n/a through <= 1.9.0.

πŸ“… Published: Oct. 29, 2024, 11:05 a.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

7.1

CVSS3.1

CVE-2024-49672 - WordPress Google Docs RSVP plugin <= 2.0.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in giffordcheung Google Docs RSVP google-docs-rsvp-guestlist allows Stored XSS.This issue affects Google Docs RSVP: from n/a through <= 2.0.1.

πŸ“… Published: Oct. 29, 2024, 11:04 a.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

7.1

CVSS3.1

CVE-2024-49673 - WordPress LaTeX2HTML plugin <= 2.5.4 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Van Abel LaTeX2HTML latex2html allows Reflected XSS.This issue affects LaTeX2HTML: from n/a through <= 2.5.4.

πŸ“… Published: Oct. 29, 2024, 11:02 a.m. πŸ”„ Last Modified: April 23, 2026, 3:19 p.m.

7.1

CVSS3.1

CVE-2024-49678 - WordPress js paper theme <= 2.5.7 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Jinwen js allows Reflected XSS.This issue affects js paper: from n/a through 2.5.7.

πŸ“… Published: Oct. 29, 2024, 11:01 a.m. πŸ”„ Last Modified: April 28, 2026, 4:10 p.m.

4.3

CVSS3.1

CVE-2024-10360 - Move Addons for Elementor <= 1.3.5 - Authenticated (Contributor+) Sensitive Information Exposure vi…

The Move Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.5 via the render function in includes/widgets/accordion/widget.php, includes/widgets/remote-template/widget.php, and other widget.php files. This makes it pos…

πŸ“… Published: Oct. 29, 2024, 11:01 a.m. πŸ”„ Last Modified: April 8, 2026, 5:31 p.m.

6.4

CVSS3.1

CVE-2024-10233 - SMSAlert - WooCommerce <= 3.7.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via sa_s…

The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sa_subscribe shortcode in all versions up to, and including, 3.7.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

πŸ“… Published: Oct. 29, 2024, 11:01 a.m. πŸ”„ Last Modified: April 8, 2026, 5:21 p.m.

6.4

CVSS3.1

CVE-2024-10266 - Premium Addons for Elementor <= 4.10.60 - Authenticated (Contributor+) DOM-Based Stored Cross-Site …

The Premium Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video Box widget in all versions up to, and including, 4.10.60 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authe…

πŸ“… Published: Oct. 29, 2024, 11:01 a.m. πŸ”„ Last Modified: April 8, 2026, 5:21 p.m.

6.4

CVSS3.1

CVE-2024-10185 - StreamWeasels YouTube Integration <= 1.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sw-youtube-embed shortcode in all versions up to, and including, 1.3.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi…

πŸ“… Published: Oct. 29, 2024, 11:01 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8101 of 34,919
Β« previous page Β» next page
Filters