9.1

CVSS3.1

CVE-2024-5450 - Bug Library < 2.1.1 - Unauthenticated RCE

The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 13, 2025, 4:22 p.m.

5.9

CVSS3.1

CVE-2024-5442 - NextGEN Gallery < 3.59.3 - Admin+ Stored XSS

The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in mul…

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 13, 2025, 4:29 p.m.

7.1

CVSS3.1

CVE-2024-5287 - WP Affiliate Platform < 6.5.1 - Profile Update via CSRF

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:59 p.m.

4.8

CVSS3.1

CVE-2024-5286 - WP Affiliate Platform < 6.5.1 - Reflected XSS via Banner Editing

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:59 p.m.

6.8

CVSS3.1

CVE-2024-5284 - WP Affiliate Platform < 6.5.1 - Stored XSS via CSRF

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:59 p.m.

6.1

CVSS3.1

CVE-2024-5283 - WP Affiliate Platform < 6.5.1 - Reflected XSS via Lead Editing

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:59 p.m.

6.1

CVSS3.1

CVE-2024-5282 - WP Affiliate Platform < 6.5.1 - Reflected XSS via Registration Form

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:58 p.m.

6.1

CVSS3.1

CVE-2024-5281 - WP Affiliate Platform < 6.5.1 - Reflected XSS via Affiliate Editing

The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:58 p.m.

4.7

CVSS3.1

CVE-2024-5280 - WP Affiliate Platform < 6.5.1 - POST Reflected XSS

The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make non-logged in users execute an XSS payload via a CSRF attack

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 19, 2025, 2:58 p.m.

8.1

CVSS3.1

CVE-2024-5167 - CM Email Registration Blacklist and Whitelist < 1.4.9 - Add/Delete Emails via CSRF Add and delete a…

The CM Email Registration Blacklist and Whitelist WordPress plugin before 1.4.9 does not have CSRF check when adding or deleting an item from the blacklist or whitelist, which could allow attackers to make a logged in admin add or delete settings from the blacklist or whitelist menu via a CSRF atta…

πŸ“… Published: July 13, 2024, 6 a.m. πŸ”„ Last Modified: May 13, 2025, 4:34 p.m.
Total resulsts: 343975
Page 8635 of 34,398
Β« previous page Β» next page
Filters