6.4
CVE-2024-5226 - Fuse Social Floating Sidebar <= 5.4.10 - Authenticated (Author+) Stored Cross-Site Scripting via Fiโฆ
The Fuse Social Floating Sidebar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the file upload functionality in all versions up to, and including, 5.4.10 due to insufficient validation of SVG files. This makes it possible for authenticated attackers, with contributor-level aโฆ
6.4
CVE-2024-5668 - Lightbox & Modal Popup WordPress Plugin โ FooBox <= 2.7.28 - Authenticated (Contributor+) Stored DOโฆ
The Lightbox & Modal Popup WordPress Plugin โ FooBox plugin for WordPress is vulnerable to DOM-based Stored Cross-Site Scripting via HTML data attributes in all versions up to, and including, 2.7.28 due to insufficient input sanitization and output escaping on user supplied attributes. This makes iโฆ
5.4
CVE-2024-6869 - Falang multilanguage for WordPress <= 1.3.52 - Missing Authorization to Translation Update and Infoโฆ
The Falang multilanguage for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.3.52. This makes it possible for authenticated attackers, with Subscriber-level access and abโฆ
4.3
CVE-2024-6987 - Orchid Store <= 1.5.6 - Missing Authorization to Authenticated (Subscriber+) Limited Plugin Activaโฆ
The Orchid Store theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'orchid_store_activate_plugin' function in all versions up to, and including, 1.5.6. This makes it possible for authenticated attackers, with Subscriber-level access and โฆ
5.3
CVE-2024-6552 - Booking for Appointments and Events Calendar โ Amelia <= 1.2 - Unauthenticated Full Path Disclosure
The Booking for Appointments and Events Calendar โ Amelia plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.2. This is due to the plugin utilizing Symfony and leaving display_errors on within test files. This makes it possible for unauthenticated attโฆ
4.3
CVE-2024-6254 - Brizy โ Page Builder <= 2.5.1 - Cross-Site Request Forgery
The Brizy โ Page Builder plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.5.1. This is due to missing or incorrect nonce validation on form submissions. This makes it possible for unauthenticated attackers to submit forms intended for public uโฆ
8.8
CVE-2024-7492 - MainWP Child Reports <= 2.2 - Cross-Site Request Forgery to Arbitrary Options Update
The MainWP Child Reports plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2. This is due to missing or incorrect nonce validation on the network_options_action() function. This makes it possible for unauthenticated attackers to update arbitrarโฆ
9.8
CVE-2024-7350 - Appointment Booking Calendar Plugin and Online Scheduling Plugin โ BookingPress 1.1.6 - 1.1.7 - Auโฆ
The Appointment Booking Calendar Plugin and Online Scheduling Plugin โ BookingPress plugin for WordPress is vulnerable to authentication bypass in versions 1.1.6 to 1.1.7. This is due to the plugin not properly verifying a user's identity prior to logging them in when completing a booking. This makโฆ
7.3
CVE-2024-38202 - Windows Update Stack Elevation of Privilege Vulnerability
Summary Microsoft was notified that an elevation of privilege vulnerability exists in Windows Update, potentially enabling an attacker with basic user privileges to reintroduce previously mitigated vulnerabilities or circumvent some features of Virtualization Based Security (VBS). However, an attacโฆ
6.7
CVE-2024-21302 - Windows Secure Kernel Mode Elevation of Privilege Vulnerability
Summary: As of July 8, 2025 Microsoft has completed mitigations to address this vulnerability. See KB5042562: Guidance for blocking rollback of virtualization-based security related updates and the Recommended Actions section of this CVE for guidance on how to protect your systems from this vulneraโฆ