4.3

CVSS3.1

CVE-2024-7417 - Royal Elementor Addons and Templates <= 1.3.986 - Authenticated (Subscriber+) Private Post Disclosu…

The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.986 via the data_fetch. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract data from password protected p…

📅 Published: Oct. 17, 2024, 3:32 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

6.1

CVSS3.1

CVE-2024-8719 - Flexmls® IDX Plugin <= 3.14.22 - Reflected Cross-Site Scripting

The Flexmls® IDX Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via several parameters like 'MaxBeds' and 'MinBeds' in all versions up to, and including, 3.14.22 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attac…

📅 Published: Oct. 17, 2024, 3:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9347 - The Ultimate WordPress Toolkit – WP Extended <= 3.0.9 - Reflected Cross-Site Scripting

The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'wpext-export' parameter in all versions up to, and including, 3.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a…

📅 Published: Oct. 17, 2024, 3:32 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

9.8

CVSS3.1

CVE-2024-9263 - WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 - Insec…

The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to Account Takeover/Privilege Escalation via Insecure Direct Object Reference in all versions up to, and including, 1.0.25 via the save() due to missing validation on a user cont…

📅 Published: Oct. 17, 2024, 3:32 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-9863 - Miniorange OTP Verification with Firebase <= 3.6.0 - Privilege Escalation via Registration due to A…

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 3.6.0 due to the insecure 'administrator' default value for the 'default_user_role' option. This makes it possible for unauthenticated attackers to register an …

📅 Published: Oct. 17, 2024, 2:06 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-9940 - Calculated Fields Form <= 5.2.45 - HTML Injection

The Calculated Fields Form plugin for WordPress is vulnerable to HTML Injection in all versions up to, and including, 5.2.45. This is due to the plugin not properly neutralizing HTML elements from submitted forms. This makes it possible for unauthenticated attackers to inject arbitrary HTML that wi…

📅 Published: Oct. 17, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 5:29 p.m.

8.8

CVSS3.1

CVE-2024-9215 - Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors <= 4.7.1 …

The Co-Authors, Multiple Authors and Guest Authors in an Author Box with PublishPress Authors plugin for WordPress is vulnerable to Insecure Direct Object Reference to Privilege Escalation/Account Takeover in all versions up to, and including, 4.7.1 via the action_edited_author() due to missing val…

📅 Published: Oct. 17, 2024, 2:06 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9240 - ReDi Restaurant Reservation <= 24.0902 - Reflected Cross-Site Scripting

The ReDi Restaurant Reservation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 24.0902. This makes it possible for unauthenticated attackers to inject arbitrary web sc…

📅 Published: Oct. 17, 2024, 2:06 a.m. 🔄 Last Modified: April 15, 2026, 2:34 p.m.

9.8

CVSS3.1

CVE-2024-9862 - Miniorange OTP Verification with Firebase <= 3.6.0 - Unauthenticated Arbitrary User Password Change

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to Arbitrary User Password Change in versions up to, and including, 3.6.0. This is due to the plugin providing user-controlled access to objects, letting a user bypass authorization and access system resources, and the…

📅 Published: Oct. 17, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 5:11 p.m.

8.1

CVSS3.1

CVE-2024-9861 - Miniorange OTP Verification with Firebase <= 3.6.0 - Authentication Bypass

The Miniorange OTP Verification with Firebase plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 3.6.0. This is due to missing validation on the token being supplied during the otp login through the plugin. This makes it possible for unauthenticated attack…

📅 Published: Oct. 17, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.
Total resulsts: 349182
Page 8257 of 34,919
« previous page » next page
Filters