6.4

CVSS3.1

CVE-2024-10014 - Flat UI Button <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via flatbtn Shortc…

The Flat UI Button plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's flatbtn shortcode in version 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level a…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: Oct. 29, 2024, 4:58 p.m.

4.4

CVSS3.1

CVE-2024-9892 - Add Widget After Content <= 2.4.6 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Add Widget After Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level perm…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.

6.1

CVSS3.1

CVE-2024-9382 - Gantry 4 Framework <= 4.1.21 - Reflected Cross-Site Scripting

The Gantry 4 Framework plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'override_id' parameter in all versions up to, and including, 4.1.21 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 5:26 p.m.

4.3

CVSS3.1

CVE-2024-9364 - SendGrid for WordPress <= 1.4 - Missing Authorization to Authenticated (Subscriber+) Log Deletion

The SendGrid for WordPress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wp_mailplus_clear_logs' function in all versions up to, and including, 1.4. This makes it possible for authenticated attackers, with Subscriber-level access and above…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

4.3

CVSS3.1

CVE-2024-9361 - Bulk images optimizer: Resize, optimize, convert to webp, rename ... <= 2.0.1 - Missing Authorizati…

The Bulk images optimizer: Resize, optimize, convert to webp, rename … plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_configuration' function in all versions up to, and including, 2.0.1. This makes it possible for authenticated…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 5:12 p.m.

6.1

CVSS3.1

CVE-2024-9383 - Parcel Pro <= 1.8.4 - Reflected Cross-Site Scripting

The Parcel Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'action' parameter in all versions up to, and including, 1.8.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-9452 - Branding <= 1.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Branding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 5:05 p.m.

6.1

CVSS3.1

CVE-2024-9350 - DPD Baltic Shipping <= 1.2.83 - Reflected Cross-Site Scripting

The DPD Baltic Shipping plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'search_value' parameter in all versions up to, and including, 1.2.83 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbit…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

6.1

CVSS3.1

CVE-2024-8740 - GetResponse Forms by Optin Cat <= 2.5.7 - Reflected Cross-Site Scripting

The GetResponse Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.7. This makes it possible for unauthenticated attackers to inject arbitrary web s…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-9373 - Elemenda <= 0.0.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Elemenda plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.0.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inje…

📅 Published: Oct. 18, 2024, 4:32 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.
Total resulsts: 349182
Page 8242 of 34,919
« previous page » next page
Filters