4.8

CVSS3.1

CVE-2024-7132 - CoBlocks < 3.1.13 - Editor+ Stored XSS

The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor and admin by default) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html cโ€ฆ

๐Ÿ“… Published: Aug. 29, 2024, 6 a.m. ๐Ÿ”„ Last Modified: Oct. 7, 2024, 3:44 p.m.

4.8

CVSS3.1

CVE-2024-6927 - Viral Signup <= 2.1 - Admin+ Stored XSS

The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

๐Ÿ“… Published: Aug. 29, 2024, 6 a.m. ๐Ÿ”„ Last Modified: Oct. 7, 2024, 3:56 p.m.

5.4

CVSS3.1

CVE-2024-5417 - Gutentor < 3.3.6 - Contributor+ Stored XSS

The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

๐Ÿ“… Published: Aug. 29, 2024, 6 a.m. ๐Ÿ”„ Last Modified: Oct. 7, 2024, 3:44 p.m.

8.8

CVSS3.1

CVE-2024-7607 - Front End Users <= 3.2.28 - Authenticated (Contributor+) Time-Based SQL Injection

The Front End Users plugin for WordPress is vulnerable to time-based SQL Injection via the โ€˜orderโ€™ parameter in all versions up to, and including, 3.2.28 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possibleโ€ฆ

๐Ÿ“… Published: Aug. 29, 2024, 5:30 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:31 p.m.

5.4

CVSS3.1

CVE-2024-5987 - WP Accessibility Helper <= 0.6.2.8 - Missing Authorization to Authenticated (Subscriber+) Limited Sโ€ฆ

The WP Accessibility Helper (WAH) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_contrast_variations' and 'save_empty_contrast_variations' functions in all versions up to, and including, 0.6.2.8. This makes it possible for authโ€ฆ

๐Ÿ“… Published: Aug. 29, 2024, 5:30 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:25 p.m.

4.4

CVSS3.1

CVE-2024-3944 - WP To Do <= 1.3.0 - Authenticated (Admin+) Stored Cross-Site Scripting via Task Comments

The WP To Do plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to iโ€ฆ

๐Ÿ“… Published: Aug. 29, 2024, 5:30 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-7606 - Front End Users <= 3.2.28 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'user-search' shortcode in all versions up to, and including, 3.2.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticateโ€ฆ

๐Ÿ“… Published: Aug. 29, 2024, 5:30 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:33 p.m.

5.3

CVSS3.1

CVE-2024-38303 -

Dell PowerEdge Platform, 14G Intel BIOS version(s) prior to 2.22.x, contains an Improper Input Validation vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure.

๐Ÿ“… Published: Aug. 29, 2024, 4:34 a.m. ๐Ÿ”„ Last Modified: Dec. 20, 2024, 2:40 p.m.

4.3

CVSS3.1

CVE-2024-7418 - The Post Grid <= 7.7.11 - Authenticated (Contributor+) Information Disclosure

The The Post Grid โ€“ Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.7.11 via the post_query_guten and post_query functions. This makes it possible for authenticated attackers, โ€ฆ

๐Ÿ“… Published: Aug. 29, 2024, 3:52 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:28 p.m.

8.1

CVSS3.1

CVE-2024-7856 - MP3 Audio Player โ€“ Music Player, Podcast Player & Radio by Sonaar <= 5.7.0.1 - Missing Authorizatioโ€ฆ

The MP3 Audio Player โ€“ Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and inโ€ฆ

๐Ÿ“… Published: Aug. 29, 2024, 3:52 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:22 p.m.
Total resulsts: 349182
Page 8707 of 34,919
ยซ previous page ยป next page
Filters