6.4

CVSS3.1

CVE-2024-5219 - Easy Google Maps <= 1.11.15 - Authenticated (Author+) Stored Cross-Site Scripting

The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level…

πŸ“… Published: July 2, 2024, 6:49 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

9.8

CVSS3.1

CVE-2024-6172 - Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & Woo…

The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to time-based SQL Injection via the db parameter in all versions up to, and including, 5.7.25 due to insufficient escaping on the user supplied paramete…

πŸ“… Published: July 2, 2024, 6:49 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

5.1

CVSS3.1

CVE-2024-0158 -

Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges

πŸ“… Published: July 2, 2024, 6:20 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 8:45 a.m.

8.8

CVSS3.1

CVE-2024-5767 - Sitetweet <= 0.2 - Stored XSS via CSRF

The sitetweet WordPress plugin through 0.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

πŸ“… Published: July 2, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

8.8

CVSS3.1

CVE-2024-5606 - Quiz And Survey Master < 9.0.2 - Contributor+ SQLi

The Quiz and Survey Master (QSM) WordPress plugin before 9.0.2 is vulnerable does not validate and escape the question_id parameter in the qsm_bulk_delete_question_from_database AJAX action, leading to a SQL injection exploitable by Contributors and above role

πŸ“… Published: July 2, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

5.4

CVSS3.1

CVE-2024-4627 - Rank Math SEO < 1.0.219 - Authenticated Stored XSS

The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin be…

πŸ“… Published: July 2, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

4.8

CVSS3.1

CVE-2024-3999 - EazyDocs < 2.5.0 - Admin+ Stored XSS

The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

πŸ“… Published: July 2, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:30 a.m.

6.4

CVSS3.1

CVE-2024-1427 - The Post Grid <= 7.7.1 - Authenticated(Contributor+) Stored Cross-Site Scripting via section title …

The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supp…

πŸ“… Published: July 2, 2024, 5:32 a.m. πŸ”„ Last Modified: April 8, 2026, 7:20 p.m.

8.8

CVSS3.1

CVE-2024-5349 - LA-Studio Element Kit for Elementor <= 1.3.8.1 - Authenticated (Contributor+) Local File Inclusion

The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.3.8.1 via the 'map_style' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitra…

πŸ“… Published: July 2, 2024, 4:31 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

6.4

CVSS3.1

CVE-2024-5419 - Void Contact Form 7 Widget For Elementor Page Builder <= 2.4 - Authenticated (Contributor+) Stored …

The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the plugin's Void Contact From 7 widget in all versions up to, and including, 2.4 due to insufficient input sanitization and outpu…

πŸ“… Published: July 2, 2024, 3:14 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.
Total resulsts: 347741
Page 9140 of 34,775
Β« previous page Β» next page
Filters