6.4

CVSS3.1

CVE-2024-5226 - Fuse Social Floating Sidebar <= 5.4.10 - Authenticated (Author+) Stored Cross-Site Scripting via Fiโ€ฆ

The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload functionality in all versions up to, and including, 5.4.10 due to insufficient validation of SVG files. This makes it possible for authenticated attackers, with contributor-level aโ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 5:31 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:38 p.m.

6.4

CVSS3.1

CVE-2024-5668 - Lightbox & Modal Popup WordPress Plugin โ€“ FooBox <= 2.7.28 - Authenticated (Contributor+) Stored DOโ€ฆ

The Lightbox & Modal Popup WordPress Plugin โ€“ FooBox plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all versions up to, and including, 2.7.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes iโ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 4:31 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:09 p.m.

5.4

CVSS3.1

CVE-2024-6869 - Falang multilanguage for WordPress <= 1.3.52 - Missing Authorization to Translation Update and Infoโ€ฆ

The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.3.52. This makes it possible for authenticated attackers, with Subscriber-level access and abโ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 4:11 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:24 p.m.

4.3

CVSS3.1

CVE-2024-6987 - Orchid Store <= 1.5.6 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activaโ€ฆ

The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with Subscriber-level access and โ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 4:11 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:53 p.m.

5.3

CVSS3.1

CVE-2024-6552 - Booking for Appointments and Events Calendar โ€“ Amelia <= 1.2 - Unauthenticated Full Path Disclosure

The Booking for Appointments and Events Calendar โ€“ Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attโ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 3:30 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-6254 - Brizy โ€“ Page Builder <= 2.5.1 - Cross-Site Request Forgery

The Brizy โ€“ Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on form submissions. This makes it possible for unauthenticated attackers to submit forms intended for public uโ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 3:30 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:01 p.m.

8.8

CVSS3.1

CVE-2024-7492 - MainWP Child Reports <= 2.2 - Cross-Site Request Forgery to Arbitrary Options Update

The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrarโ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 2:32 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:24 p.m.

9.8

CVSS3.1

CVE-2024-7350 - Appointment Booking Calendar Plugin and Online Scheduling Plugin โ€“ BookingPress 1.1.6 - 1.1.7 - Auโ€ฆ

The Appointment Booking Calendar Plugin and Online Scheduling Plugin โ€“ BookingPress plugin for WordPress is vulnerable to authentication bypass in versions 1.1.6 to 1.1.7. This is due to the plugin not properly verifying a user's identity prior to logging them in when completing a booking. This makโ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 2:32 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.3

CVSS3.1

CVE-2024-38202 - Windows Update Stack Elevation of Privilege Vulnerability

Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS). However, an attacโ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 1:59 a.m. ๐Ÿ”„ Last Modified: July 10, 2025, 4:33 p.m.

6.7

CVSS3.1

CVE-2024-21302 - Windows Secure Kernel Mode Elevation of Privilege Vulnerability

Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulneraโ€ฆ

๐Ÿ“… Published: Aug. 8, 2024, 1:59 a.m. ๐Ÿ”„ Last Modified: July 10, 2025, 5:15 p.m.
Total resulsts: 349182
Page 8918 of 34,919
ยซ previous page ยป next page
Filters