6.4

CVSS3.1

CVE-2024-3666 - Opal Estate Pro – Property Management and Submission <= 1.7.6 - Authenticated (Contributor+) Stored…

The Opal Estate Pro – Property Management and Submission plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the agent latitude and longitude parameters in all versions up to, and including, 1.7.6 due to insufficient input sanitization and output escaping. This makes it possible f…

📅 Published: May 22, 2024, 7:37 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

5.5

CVSS3.1

CVE-2024-2953 - LuckyWP Table of Contents <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple parameters in versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with Contributor permissions…

📅 Published: May 22, 2024, 7:37 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

7.5

CVSS3.1

CVE-2024-4157 - Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder <= 5.1.15 - P…

The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 5.1.15 via deserialization of untrusted input in the extractDynamicValues function. This makes it possible for a…

📅 Published: May 22, 2024, 7:37 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

4.4

CVSS3.1

CVE-2023-6487 - LuckyWP Table of Contents <= 2.1.5 - Authenticated (Administrator+) Cross-Site Scripting

The LuckyWP Table of Contents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Header Title' field in all versions up to and including 2.1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-l…

📅 Published: May 22, 2024, 7:37 a.m. 🔄 Last Modified: April 8, 2026, 6:18 p.m.

6.1

CVSS3.1

CVE-2024-2119 - LuckyWP Table of Contents <= 2.1.5 - Reflected Cross-Site Scripting

The LuckyWP Table of Contents plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the attrs parameter in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary…

📅 Published: May 22, 2024, 7:37 a.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.

4.4

CVSS3.1

CVE-2024-0632 - Automatic Translator with Google Translate <= 1.5.4 - Authenticated (Administrator+) Stored Cross-S…

The Automatic Translator with Google Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom font setting in all versions up to, and including, 1.5.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, wi…

📅 Published: May 22, 2024, 7:37 a.m. 🔄 Last Modified: April 8, 2026, 6:18 p.m.

6.4

CVSS3.1

CVE-2024-2163 - Ninja Beaver Add-ons for Beaver Builder <= 2.4.5 - Authenticated (Contributor+) Stored Cross-Site …

The Ninja Beaver Add-ons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.4.5 due to insufficient input sanitization and output escaping on user supplied attributes such as urls. This makes it possi…

📅 Published: May 22, 2024, 7:37 a.m. 🔄 Last Modified: April 8, 2026, 5:18 p.m.

6.4

CVSS3.1

CVE-2024-3671 - Print-O-Matic <= 2.1.10 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

The Print-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'print-me' shortcode in all versions up to, and including, 2.1.10 due to insufficient input sanitization and output escaping on user supplied attributes such as 'tag'. This makes it possible for aut…

📅 Published: May 22, 2024, 7:37 a.m. 🔄 Last Modified: April 8, 2026, 4:36 p.m.

6.4

CVSS3.1

CVE-2024-3198 - WP Font Awesome Share Icons <= 1.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The WP Font Awesome Share Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpfai_social' shortcode in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fo…

📅 Published: May 22, 2024, 6:50 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.1

CVSS3.1

CVE-2024-1762 - NextScripts: Social Networks Auto-Poster <= 4.4.3 - Unauthenticated Stored Cross-Site Scripting via…

The NextScripts: Social Networks Auto-Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the HTTP_USER_AGENT header in all versions up to, and including, 4.4.3 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers …

📅 Published: May 22, 2024, 6:50 a.m. 🔄 Last Modified: April 8, 2026, 6:20 p.m.
Total resulsts: 343968
Page 9184 of 34,397
« previous page » next page
Filters