7.2

CVSS3.1

CVE-2024-8757 - Boost Your Blog's Engagement with WP Post Author <= 3.8.1 - Authenticated (Administrator+) SQL Inje…

The WP Post Author – Boost Your Blog&#039;s Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_user_id parameter in all versions up to, and i…

📅 Published: Oct. 12, 2024, 9:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-8902 - Elementor Addon Elements <= 1.13.8 - Authenticated (Contributor+) Sensitive Information Exposure vi…

The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in modules/data-table/widgets/data-table.php. This makes it possible for authenticated attackers, with Contributor-level acce…

📅 Published: Oct. 12, 2024, 9:39 a.m. 🔄 Last Modified: April 8, 2026, 5 p.m.

6.4

CVSS3.1

CVE-2024-9595 - TablePress <= 2.4.2 - Authenticated (Author+) Stored Cross-Site Scripting

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wit…

📅 Published: Oct. 12, 2024, 8:41 a.m. 🔄 Last Modified: April 8, 2026, 5:35 p.m.

6.4

CVSS3.1

CVE-2024-9696 - Rescue Shortcodes <= 2.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated …

📅 Published: Oct. 12, 2024, 8:41 a.m. 🔄 Last Modified: April 8, 2026, 5:09 p.m.

5.3

CVSS3.1

CVE-2024-8760 - Stackable – Page Builder Gutenberg Blocks <= 3.13.6 - Unauthenticated CSS Injection

The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers to embed untrusted style information into comments resulting in a possibility of data exfiltration suc…

📅 Published: Oct. 12, 2024, 8:41 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-8915 - Category Icon <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload

The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to…

📅 Published: Oct. 12, 2024, 8:40 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-9704 - Social Sharing (by Danny) <= 1.3.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via S…

The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible …

📅 Published: Oct. 12, 2024, 6:51 a.m. 🔄 Last Modified: April 8, 2026, 4:56 p.m.

9.8

CVSS3.1

CVE-2024-9047 - WordPress File Upload <= 4.24.11 - Unauthenticated Path Traversal to Arbitrary File Read and Deleti…

The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitatio…

📅 Published: Oct. 12, 2024, 6:51 a.m. 🔄 Last Modified: April 8, 2026, 4:53 p.m.

4.3

CVSS3.1

CVE-2024-9756 - Order Attachments for WooCommerce 2.0 - 2.4.1 - Missing Authorization to Authenticated (Subscriber+…

The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authenticated attackers, with subscriber-level access…

📅 Published: Oct. 12, 2024, 6:51 a.m. 🔄 Last Modified: Nov. 25, 2024, 8:49 p.m.

6.1

CVSS3.1

CVE-2024-9670 - 2D Tag Cloud <= 6.0.2 - Reflected Cross-Site Scripting via add_query_arg Parameter

The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 6.0.2. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th…

📅 Published: Oct. 12, 2024, 5:39 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8307 of 34,919
« previous page » next page
Filters