6.4

CVSS3.1

CVE-2024-5457 - Panda Video <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Panda Video plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the โ€˜idโ€™ parameter in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and abovโ€ฆ

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:22 p.m.

5.3

CVSS3.1

CVE-2024-3228 - Social Sharing Plugin โ€“ Kiwi <= 2.1.7 - Information Disclosure

The Social Sharing Plugin โ€“ Kiwi plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.1.7 via the 'kiwi-nw-pinterest' class. This makes it possible for unauthenticated attackers to view limited content from password protected posts.

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3603 - OSM โ€“ OpenStreetMap <= 6.0.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcoโ€ฆ

The OSM โ€“ OpenStreetMap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'osm_map' shortcode in all versions up to, and including, 6.0.3 due to insufficient input sanitization and output escaping on user supplied attributes such as 'theme'. This makes it possible fโ€ฆ

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:21 p.m.

5.4

CVSS3.1

CVE-2024-5648 - LearnDash LMS - Reports Free <= 1.8.2.1 - Missing Authorization to Plugin Settings Update

The LearnDash LMS โ€“ Reports plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions (i.e. wrld_set_configuration, wrld_exclude_settings_save, apply_time_tracking_settings, wp_ajax_wrld_gutenberg_block_visit, etc..) in all versioโ€ฆ

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-5856 - Comment Images Reloaded <= 2.2.1 - Authenticated (Subscriber+) Arbitrary Media Deletion

The Comment Images Reloaded plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the cir_delete_image AJAX action in all versions up to, and including, 2.2.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, โ€ฆ

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-4100 - Pricing Table <= 2.0.1 - Cross-Site Request Forgery via ajax()

The Pricing Table plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.1. This is due to missing or incorrect nonce validation on the ajax() function. This makes it possible for unauthenticated attackers to perform a variety of actions related tโ€ฆ

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-4868 - Extensions for Elementor <= 2.0.32 - Authenticated (Contributor+) Stored Cross-Site Scripting via Eโ€ฆ

The Extensions for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's EE Events and EE Flipbox widgets in all versions up to, and including, 2.0.32 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possiblโ€ฆ

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 6:21 p.m.

5.4

CVSS3.1

CVE-2024-5600 - Happy SCSS Compiler - Compile SCSS to CSS automatically <= 1.3.10 - Missing Authorization to Authenโ€ฆ

The SCSS Happy Compiler โ€“ Compile SCSS to CSS & Automatic Enqueue plugin for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check and insufficient sanitization on the import_settings() function in all versions up to, and including, 1.3.10. This makes it possible โ€ฆ

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-3608 - Product Designer <= 1.0.33 - Missing Authorization to Unauthenticated Arbitrary Attachment Deletion

The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attaโ€ฆ

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-5810 - WP2Speed Faster โ€“ Optimize PageSpeed Insights Score 90-100 <= 1.0.1 - Improper Authorization due toโ€ฆ

The WP2Speed Faster โ€“ Optimize PageSpeed Insights Score 90-100 plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 1.0.1. This is due to the use of hardcoded credentials to authenticate all the incoming API requests. This makes it possible for unauthenticโ€ฆ

๐Ÿ“… Published: July 9, 2024, 8:33 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348147
Page 9130 of 34,815
ยซ previous page ยป next page
Filters