5.9

CVSS3.1

CVE-2024-9156 - TI WooCommerce Wishlist <= 2.8.2 - Unauthenticated SQL Injection via lang parameters

The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries …

📅 Published: Oct. 10, 2024, 6 a.m. 🔄 Last Modified: Oct. 15, 2024, 2:40 p.m.

6.4

CVSS3.1

CVE-2024-9074 - Advanced Blocks Pro <= 1.0.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upl…

The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abo…

📅 Published: Oct. 10, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 5:33 p.m.

6.3

CVSS3.1

CVE-2024-9520 - UserPlus <= 2.0 - Missing Authorization via Multiple Functions

The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including, 2.0. This makes it possible for authenticated attackers with subscriber-level permissions or above, to…

📅 Published: Oct. 10, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 5:30 p.m.

4.3

CVSS3.1

CVE-2024-9067 - Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress <= 1…

The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'delete_attachment' function in all versions up to, and including, 1.3.0. This makes it…

📅 Published: Oct. 10, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.

4.3

CVSS3.1

CVE-2024-8477 - Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) <= 3.1.87 - Cro…

The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on the Init() function. This makes it possible …

📅 Published: Oct. 10, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 5:28 p.m.

7.2

CVSS3.1

CVE-2024-9022 - TS Poll – Survey, Versus Poll, Image Poll, Video Poll <= 2.4.0 - Authenticated (Administrator+) SQL…

The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.4.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL qu…

📅 Published: Oct. 10, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.

6.1

CVSS3.1

CVE-2024-8729 - Easy Social Share Buttons <= 1.4.5 - Reflected Cross-Site Scripting

The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.5. This makes it possible for unauthenticated attackers to inject arbitrary web script…

📅 Published: Oct. 10, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 5:17 p.m.

4.3

CVSS3.1

CVE-2024-9685 - Notification for Telegram <= 3.3.1 - Missing Authorization to Authenticated (Subscriber+) Send Tele…

The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nftb_test_action' function in versions up to, and including, 3.3.1. This makes it possible for authenticated attackers, with subscriber-level access and ab…

📅 Published: Oct. 10, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 5:14 p.m.

6.4

CVSS3.1

CVE-2024-9057 - Curator.io: Show all your social media posts in a beautiful feed. <= 1.9.1 - Authenticated (Contrib…

The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘feed_id’ attribute in all versions up to, and including, 1.9.1 due to insufficient input sanitization and output escaping. This makes it possible for auth…

📅 Published: Oct. 10, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

7.3

CVSS3.1

CVE-2024-9581 - Shortcodes AnyWhere <= 1.0.1 - Unauthenticated Arbitrary Shortcode Execution

The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for un…

📅 Published: Oct. 10, 2024, 2:06 a.m. 🔄 Last Modified: April 8, 2026, 5:03 p.m.
Total resulsts: 349182
Page 8332 of 34,919
« previous page » next page
Filters