5.3

CVSS3.1

CVE-2024-3228 - Social Sharing Plugin – Kiwi <= 2.1.7 - Information Disclosure

The Social Sharing Plugin – Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' class. This makes it possible for unauthenticated attackers to view limited content from password protected posts.

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3603 - OSM – OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortco…

The OSM – OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' shortcode in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user supplied attributes such as 'theme'. This makes it possible f…

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

5.4

CVSS3.1

CVE-2024-5648 - LearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Update

The LearnDash LMS – Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. wrld_set_configuration, wrld_exclude_settings_save, apply_time_tracking_settings, wp_ajax_wrld_gutenberg_block_visit, etc..) in all versio…

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

4.3

CVSS3.1

CVE-2024-5856 - Comment Images Reloaded <= 2.2.1 - Authenticated (Subscriber+) Arbitrary Media Deletion

The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, …

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

5.3

CVSS3.1

CVE-2024-4100 - Pricing Table <= 2.0.1 - Cross-Site Request Forgery via ajax()

The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing or incorrect nonce validation on the ajax() function. This makes it possible for unauthenticated attackers to perform a variety of actions related t…

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-4868 - Extensions for Elementor <= 2.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via E…

The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's EE Events and EE Flipbox widgets in all versions up to, and including, 2.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibl…

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

5.4

CVSS3.1

CVE-2024-5600 - Happy SCSS Compiler - Compile SCSS to CSS automatically <= 1.3.10 - Missing Authorization to Authen…

The SCSS Happy Compiler – Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check and insufficient sanitization on the import_settings() function in all versions up to, and including, 1.3.10. This makes it possible …

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

5.3

CVSS3.1

CVE-2024-3608 - Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary atta…

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

5.3

CVSS3.1

CVE-2024-5810 - WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 <= 1.0.1 - Improper Authorization due to…

The WP2Speed Faster – Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthentic…

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

4.3

CVSS3.1

CVE-2024-5704 - XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin] <= 1.7.0 - Missing Authorizat…

The XPlainer – WooCommerce Product FAQ [WooCommerce Accordion FAQ Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. ffw_insert_new_faq, ffw_hide_discount_notice, ffw_delete_all_faqs, ffw_delete_single_faq, etc…

📅 Published: July 9, 2024, 8:33 a.m. 🔄 Last Modified: April 8, 2026, 5:19 p.m.
Total resulsts: 343436
Page 8659 of 34,344
« previous page » next page
Filters