4.4

CVSS3.1

CVE-2024-6520 - Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - A…

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom error message in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it…

📅 Published: July 27, 2024, 11:37 a.m. 🔄 Last Modified: April 8, 2026, 5:19 p.m.

6.4

CVSS3.1

CVE-2024-6897 - aThemes Starter Sites <= 1.0.53 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File …

The aThemes Starter Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.53 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and …

📅 Published: July 27, 2024, 11:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-6521 - Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.19 - A…

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dropdown fields in all versions up to, and including, 5.1.19 due to insufficient input sanitization and output escaping. This makes it poss…

📅 Published: July 27, 2024, 11:13 a.m. 🔄 Last Modified: April 8, 2026, 7:22 p.m.

6.4

CVSS3.1

CVE-2024-6627 - Happy Addons for Elementor <= 3.11.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's PDF View widget in all versions up to, and including, 3.11.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic…

📅 Published: July 27, 2024, 11:13 a.m. 🔄 Last Modified: April 8, 2026, 4:55 p.m.

5.3

CVSS3.1

CVE-2024-5614 - Piotnet Addons For Elementor <= 2.4.29 - Unauthenticated Sensitive Information Exposure

The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.4.29 via the 'pafe_posts_list' function. This makes it possible for unauthenticated attackers to extract sensitive data including titles and excerpts of futu…

📅 Published: July 27, 2024, 11:13 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-6458 - WooCommerce Product Table Lite <= 3.5.1 - Missing Authorization to (Subscriber+) Stored Cross-Site …

The WooCommerce Product Table Lite plugin for WordPress is vulnerable to unauthorized post title modification due to a missing capability check on the wcpt_presets__duplicate_preset_to_table function in all versions up to, and including, 3.5.1. This makes it possible for authenticated attackers wit…

📅 Published: July 27, 2024, 8:36 a.m. 🔄 Last Modified: April 8, 2026, 5:28 p.m.

5.3

CVSS3.1

CVE-2024-6569 - Campaign Monitor for WordPress <= 2.8.15 - Unauthenticated Full Path Disclosure

The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due the plugin not properly restricting direct access to /forms/views/admin/create.php and display_errors being enabled. This makes it possible for una…

📅 Published: July 27, 2024, 8:36 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

5.8

CVSS3.1

CVE-2024-5969 - AIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email Sending

The AIomatic - Automatic AI Content Writer for WordPress is vulnerable to arbitrary email sending vulnerability in versions up to, and including, 2.0.5. This is due to insufficient limitations on the email recipient and the content in the 'aiomatic_send_email' function which are reachable via AJAX.…

📅 Published: July 27, 2024, 7:33 a.m. 🔄 Last Modified: April 8, 2026, 5:19 p.m.

5.3

CVSS3.1

CVE-2024-6546 - One Click Close Comments <= 2.7.1 - Unauthenticated Full Path Disclosure

The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due to the plugin utilizing bootstrap and leaving test files with display_errors on. This makes it possible for unauthenticated attackers to retrieve the full…

📅 Published: July 27, 2024, 1:51 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-6634 - Master Currency WP <= 1.1.61 - Authenticated (Contributor+) Stored Cross-Site Scripting via Currenc…

The Master Currency WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's currencyconverterform shortcode in all versions up to, and including, 1.1.61 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

📅 Published: July 27, 2024, 1:51 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 344980
Page 8623 of 34,498
« previous page » next page
Filters