4.3

CVSS3.1

CVE-2024-6872 - Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-…

The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks! – TemplateSpare plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'templatespare_activ…

πŸ“… Published: Aug. 3, 2024, 11:37 a.m. πŸ”„ Last Modified: April 8, 2026, 5:12 p.m.

4.3

CVSS3.1

CVE-2024-6709 - Sync Post With Other Site <= 1.6 - Missing Authorization to Authenticated (Subscriber+) Post Creati…

The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all versions up to, and including, 1.6. This makes it possible for authenticated attackers, with Subscriber-level access a…

πŸ“… Published: Aug. 3, 2024, 11:37 a.m. πŸ”„ Last Modified: April 8, 2026, 4:47 p.m.

6.4

CVSS3.1

CVE-2024-7356 - Zephyr Project Manager <= 3.3.100 - Authenticated (Subscriber+) Stored Cross-Site Scripting via fil…

The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Subscriber-lev…

πŸ“… Published: Aug. 3, 2024, 9:37 a.m. πŸ”„ Last Modified: April 8, 2026, 5:26 p.m.

9.8

CVSS3.1

CVE-2024-7257 - YayExtra – WooCommerce Extra Product Options <= 1.3.7 - Unauthenticated Arbitrary File Upload via h…

The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions up to, and including, 1.3.7. This makes it possible for unauthenticated attackers to upload arbitrary …

πŸ“… Published: Aug. 3, 2024, 9:37 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-7031 - File Manager Pro – Filester <= 1.8.2 - Authenticated Plugin Settings Update

The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, with a role tha…

πŸ“… Published: Aug. 3, 2024, 8:36 a.m. πŸ”„ Last Modified: April 8, 2026, 5:15 p.m.

7.2

CVSS3.1

CVE-2024-7291 - JetFormBuilder <= 3.3.4.1 - Authenticated (Administrator+) Privilege Escalation

The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it possible for authenticated attackers, with administrator-level and above permissions, to register as su…

πŸ“… Published: Aug. 3, 2024, 6:41 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.5

CVSS3.1

CVE-2024-6477 - UsersWP < 1.2.12 - Users Information Disclosure

The UsersWP WordPress plugin before 1.2.12 uses predictable filenames when an admin generates an export, which could allow unauthenticated attackers to download them and retrieve sensitive information such as IP, username, and email address

πŸ“… Published: Aug. 3, 2024, 6 a.m. πŸ”„ Last Modified: Aug. 27, 2025, noon

5.9

CVSS3.1

CVE-2024-6390 - Quiz and Survey Master (QSM) < 9.1.0 - Contributor+ Stored XSS

The Quiz and Survey Master (QSM) WordPress plugin before 9.1.0 does not properly sanitise and escape some of its Quizz settings, which could allow high privilege users such as contributor to perform Stored Cross-Site Scripting attacks

πŸ“… Published: Aug. 3, 2024, 6 a.m. πŸ”„ Last Modified: June 6, 2025, 4:10 p.m.

5.3

CVSS3.1

CVE-2024-42349 - FOG has a Log Information Disclosure

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.4 and earlier can leak authorized and rejected logins via logs stored directly on the root of the web server. FOG Server creates 2 logs on the root of the web server (fog_login_accepted.log and fog_login_failed.…

πŸ“… Published: Aug. 2, 2024, 8:01 p.m. πŸ”„ Last Modified: Sept. 10, 2024, 4:44 p.m.

9.3

CVSS3.1

CVE-2024-42348 - FOG leaks sensitive information (AD domain, username and password)

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395.

πŸ“… Published: Aug. 2, 2024, 7:58 p.m. πŸ”„ Last Modified: Sept. 10, 2024, 4:49 p.m.
Total resulsts: 349182
Page 8963 of 34,919
Β« previous page Β» next page
Filters