7.2

CVSS3.1

CVE-2024-9314 - Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Authenticated (Administrator+) P…

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.228 via deserialization of untrusted input 'set_redirections' function. This makes it possible for authenticated attackers, with Administrat…

πŸ“… Published: Oct. 5, 2024, 11:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:15 p.m.

6.5

CVSS3.1

CVE-2024-9161 - Rank Math SEO – AI SEO Tools to Dominate SEO Rankings <= 1.0.228 - Missing Authorization to Unauthe…

The Rank Math SEO – AI SEO Tools to Dominate SEO Rankings plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'update_metadata' function in all versions up to, and including, 1.0.228. This makes it possible for unauthenticated at…

πŸ“… Published: Oct. 5, 2024, 11:21 a.m. πŸ”„ Last Modified: April 8, 2026, 5:02 p.m.

7.5

CVSS3.1

CVE-2024-44016 - WordPress Podiant plugin <= 1.1 - Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in amarksteadman Podiant podiant allows PHP Local File Inclusion.This issue affects Podiant: from n/a through <= 1.1.

πŸ“… Published: Oct. 5, 2024, 11:01 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

7.5

CVSS3.1

CVE-2024-44015 - WordPress Users Control plugin <= 1.0.16 - Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in istmoplugins Users Control users-control allows PHP Local File Inclusion.This issue affects Users Control: from n/a through <= 1.0.16.

πŸ“… Published: Oct. 5, 2024, 10:57 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

9.6

CVSS3.1

CVE-2024-44014 - WordPress Vmax Project Manager plugin <= 1.0 - Local File Inclusion to RCE vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Vmax Studio Vmax Project Manager vmax-project-manager allows PHP Local File Inclusion.This issue affects Vmax Project Manager: from n/a through <= 1.0.

πŸ“… Published: Oct. 5, 2024, 10:53 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

7.5

CVSS3.1

CVE-2024-44013 - WordPress VR Calendar plugin <= 2.4.0 - Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through <= 2.4.0.

πŸ“… Published: Oct. 5, 2024, 10:37 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

7.5

CVSS3.1

CVE-2024-44012 - WordPress WP Newsletter Subscription plugin <= 1.1 - Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in wpdev33 WP Newsletter Subscription wp-newsletter-subscription allows PHP Local File Inclusion.This issue affects WP Newsletter Subscription: from n/a through <= 1.1.

πŸ“… Published: Oct. 5, 2024, 10:34 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

7.5

CVSS3.1

CVE-2024-44011 - WordPress WP Ticket Ultra plugin <= 1.0.5 - Local File Inclusion vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ExpressTech Systems WP Ticket Ultra Help Desk & Support Plugin wp-ticket-ultra allows PHP Local File Inclusion.This issue affects WP Ticket Ultra Help Desk & Support Plugin: from n/a through <= 1.0.5.

πŸ“… Published: Oct. 5, 2024, 10:33 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

4.9

CVSS3.1

CVE-2024-9146 - WordPress CSS JS Files plugin <= 1.5.0 - Directory Traversal to File Read vulnerability

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in jamesdlow CSS JS Files css-js-files allows Path Traversal.This issue affects CSS JS Files: from n/a through <= 1.5.0.

πŸ“… Published: Oct. 5, 2024, 10:31 a.m. πŸ”„ Last Modified: April 23, 2026, 3:22 p.m.

6.1

CVSS3.1

CVE-2024-9417 - Hash Form - Drag & Drop Form Builder <= 1.1.9 - Unauthenticated Limited File Upload

The Hash Form – Drag & Drop Form Builder plugin for WordPress is vulnerable to limited file uploads due to a misconfigured file type validation in the 'handleUpload' function in all versions up to, and including, 1.1.9. This makes it possible for unauthenticated attackers to upload files that are e…

πŸ“… Published: Oct. 5, 2024, 9:39 a.m. πŸ”„ Last Modified: April 8, 2026, 5:23 p.m.
Total resulsts: 349182
Page 8397 of 34,919
Β« previous page Β» next page
Filters