7.5
CVE-2024-44017 - WordPress MH Board plugin <= 1.3.2.1 - Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in MinHyeong Lim MH Board mh-board allows PHP Local File Inclusion.This issue affects MH Board: from n/a through <= 1.3.2.1.
7.2
CVE-2024-44030 - WordPress Checkout Mestres WP plugin <= 8.6 - Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mestres do WP Checkout Mestres WP checkout-mestres-wp allows Absolute Path Traversal.This issue affects Checkout Mestres WP: from n/a through <= 8.6.
6.1
CVE-2024-9218 - Magazine Blocks โ Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocโฆ
The Magazine Blocks โ Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3โฆ
6.1
CVE-2024-9378 - YML for Yandex Market <= 4.7.2 - Reflected Cross-Site Scripting
The YML for Yandex Market plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 4.7.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary weโฆ
6.1
CVE-2024-9344 - BerqWP โ Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Imagesโฆ
The BerqWP โ Automated All-In-One PageSpeed Optimization Plugin for Core Web Vitals, Cache, CDN, Images, CSS, and JavaScript plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'url' parameter in all versions up to, and including, 2.1.1 due to insufficient input sanitizatioโฆ
6.1
CVE-2024-8800 - RabbitLoader โ Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Opโฆ
The RabbitLoader โ Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and includiโฆ
6.1
CVE-2024-9210 - MC4WP: Mailchimp Top Bar <= 1.6.0 - Reflected Cross-Site Scripting
The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.6.0. This makes it possible for unauthenticated attackers to inject arbitrary web scriptsโฆ
6.1
CVE-2024-9222 - Paid Membership Subscriptions โ Effortless Memberships, Recurring Payments & Content Restriction <=โฆ
The Paid Membership Subscriptions โ Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.12.8. This makes โฆ
6.1
CVE-2024-9225 - SEOPress โ On-site SEO <= 8.1.1 - Reflected Cross-Site Scripting
The SEOPress โ On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 8.1.1. This makes it possible for unauthenticated attackers to inject arbiโฆ
6.4
CVE-2024-9172 - Demo Importer Plus <= 2.0.1 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Uploโฆ
The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and abovโฆ