6.1

CVSS3.1

CVE-2024-8713 - Kodex Posts likes <= 2.5.0 - Reflected Cross-Site Scripting

The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.0. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag…

📅 Published: Sept. 25, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 4:49 p.m.

6.4

CVSS3.1

CVE-2024-9068 - OneElements – Best Elementor Addons <= 1.3.7 - Authenticated (Author+) Stored Cross-Site Scripting …

The OneElements – Best Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-leve…

📅 Published: Sept. 25, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 4:48 p.m.

7.2

CVSS3.1

CVE-2024-7617 - Contact Form to Any API <= 1.2.4 - Unauthenticated Stored Cross-Site Scripting via Contact Form

The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fields in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitra…

📅 Published: Sept. 25, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-9069 - Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Bea…

The Graphicsly – The ultimate graphics plugin for WordPress website builder ( Gutenberg, Elementor, Beaver Builder, WPBakery ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization an…

📅 Published: Sept. 25, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 4:45 p.m.

6.1

CVSS3.1

CVE-2024-8741 - Beam me up Scotty – Back to Top Button <= 1.0.21 - Reflected Cross-Site Scripting

The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.21. This makes it possible for unauthenticated attackers to inject arbitr…

📅 Published: Sept. 25, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 4:45 p.m.

5.3

CVSS3.1

CVE-2024-7426 - Community by PeepSo – Social Network, Membership, Registration, User Profiles <= 6.4.6.0 - Unauthen…

The Community by PeepSo – Social Network, Membership, Registration, User Profiles plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 6.4.6.0. This is due to the plugin displaying errors and allowing direct access to the sse.php file. This makes it possi…

📅 Published: Sept. 25, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 5:19 p.m.

6.4

CVSS3.1

CVE-2024-9027 - WPZOOM Shortcodes <= 1.0.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via box Short…

The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attac…

📅 Published: Sept. 25, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 4:43 p.m.

6.1

CVSS3.1

CVE-2024-8549 - Simple Calendar – Google Calendar Plugin <= 3.4.2 - Reflected Cross-Site Scripting

The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2. This makes it possible for unauthenticated attackers to inject arbit…

📅 Published: Sept. 25, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

7.3

CVSS3.1

CVE-2024-8481 - Special Text Boxes <= 6.2.4 - Unauthenticated Arbitrary Shortcode Execution

The The Special Text Boxes plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 6.2.4. This is due to the plugin adding the filter add_filter('comment_text', 'do_shortcode'); which will run all shortcodes in comments. This makes it possible for u…

📅 Published: Sept. 25, 2024, 2:05 a.m. 🔄 Last Modified: April 8, 2026, 5:19 p.m.

4.3

CVSS3.1

CVE-2024-7386 - Premium Packages – Sell Digital Products Securely <= 5.9.1 - Cross-Site Request Forgery

The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.1. This is due to missing nonce validation on the addRefund() function. This makes it possible for unauthenticated attackers to perform ac…

📅 Published: Sept. 25, 2024, 2:04 a.m. 🔄 Last Modified: April 8, 2026, 4:34 p.m.
Total resulsts: 349182
Page 8481 of 34,919
« previous page » next page
Filters