6.1

CVSS3.1

CVE-2024-8786 - Auto Featured Image from Title <= 2.3 - Reflected Cross-Site Scripting

The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.3. This makes it possible for unauthenticated attackers to inject arbitrary web scr…

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-9018 - WP Easy Gallery <= 4.8.5 - Authenticated (Contributor+) SQL Injection via key Parameter

The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜key’ parameter in all versions up to, and including, 4.8.5 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.…

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:12 p.m.

6.1

CVSS3.1

CVE-2024-9220 - LH Copy Media File <= 1.08 - Reflected Cross-Site Scripting

The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.08. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag…

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.1

CVSS3.1

CVE-2024-8793 - Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More <= …

The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.7.2.1. This makes …

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-8288 - Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg <= 1.2.4 - Authenticat…

The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜align’ attribute within the 'wp:guten-post-layout/post-grid' Gutenberg block in all versions up to, and including, 1.2.4 due to insufficient in…

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9228 - Loggedin – Limit Active Logins <= 1.3.1 - Reflected Cross-Site Scripting

The Loggedin – Limit Active Logins plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.3.1. This makes it possible for unauthenticated attackers to inject arbitrary web s…

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.1

CVSS3.1

CVE-2024-8799 - Custom Banners <= 3.3 - Reflected Cross-Site Scripting

The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages th…

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:50 p.m.

6.5

CVSS3.1

CVE-2024-9224 - Hello World <= 2.1.1 - Authenticated (Subscriber+) Arbitrary File Read

The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This makes it possible for authenticated attackers, with subscriber-level access and above, to read the contents of arbitrary files on the s…

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:44 p.m.

6.1

CVSS3.1

CVE-2024-9209 - WP Search Analytics <= 1.4.10 - Reflected Cross-Site Scripting

The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.10. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in …

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

6.1

CVSS3.1

CVE-2024-9241 - PDF Image Generator <= 1.5.6 - Reflected Cross-Site Scripting

The PDF Image Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p…

πŸ“… Published: Oct. 1, 2024, 8:30 a.m. πŸ”„ Last Modified: April 8, 2026, 4:36 p.m.
Total resulsts: 349182
Page 8427 of 34,919
Β« previous page Β» next page
Filters