0.0

CVE-2024-34828 - WordPress Church Admin plugin <= 4.1.32 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.32.

πŸ“… Published: May 10, 2024, 8:16 a.m. πŸ”„ Last Modified: April 1, 2026, 4:17 p.m.

6.1

CVSS3.1

CVE-2024-3547 - Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Reflected Cross-Sit…

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'google_connect_error' parameter in all versions up to, and including, 1.5.102 due to insufficient input sanitization and output escaping. This makes i…

πŸ“… Published: May 10, 2024, 7:33 a.m. πŸ”„ Last Modified: Jan. 30, 2025, 4:10 p.m.

6.4

CVSS3.1

CVE-2024-4398 - HTML5 Audio Player- Best WordPress Audio Player Plugin <= 2.2.19 - Authenticated (Contributor+) Sto…

The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po…

πŸ“… Published: May 10, 2024, 7:33 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:42 a.m.

6.4

CVSS3.1

CVE-2024-4275 - Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= …

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Interactive Circle widget in all versions up to, and including, 5.9.19 due to insufficient input sanitization and ou…

πŸ“… Published: May 10, 2024, 7:33 a.m. πŸ”„ Last Modified: Jan. 15, 2025, 5:58 p.m.

7.2

CVSS3.1

CVE-2024-2662 - Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 1.5.102 - Authenticated (Admi…

The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to command injection in all versions up to, and including, 1.5.102. This is due to insufficient filtering of template attributes during the creation of HTML for custom widgets This makes it pos…

πŸ“… Published: May 10, 2024, 7:33 a.m. πŸ”„ Last Modified: Jan. 30, 2025, 4:12 p.m.

6.4

CVSS3.1

CVE-2024-4449 - Essential Addons for Elementor <= 5.9.19 - Authenticated (Contributor+) DOM-Based Stored Cross-Sit…

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Fancy Text', 'Filter Gallery', 'Sticky Video', 'Content Ticker', 'Woo Product Gallery', & 'Twitter Feed' widgets in…

πŸ“… Published: May 10, 2024, 7:33 a.m. πŸ”„ Last Modified: Jan. 15, 2025, 6 p.m.

6.5

CVSS3.1

CVE-2024-4448 - Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= …

The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'Dual Color Header', 'Event Calendar', & 'Advanced Data Table' widgets in all versions up to, and including, 5.9.19 …

πŸ“… Published: May 10, 2024, 7:33 a.m. πŸ”„ Last Modified: Jan. 15, 2025, 5:59 p.m.

8.8

CVSS3.1

CVE-2024-4129 - Authentication bypass in Snow License Manager

Improper Authentication vulnerability in Snow Software AB Snow License Manager on Windows allows a networked attacker to perform an Authentication Bypass if Active Directory Authentication is enabled.This issue affects Snow License Manager: from 9.33.2 through 9.34.0.

πŸ“… Published: May 10, 2024, 6:55 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:42 a.m.

8.8

CVSS3.1

CVE-2024-3828 - Spectra Pro <= 1.1.5 - Authenticated (Author+) Privilege Escalation

The Spectra Pro plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.1.5. This is due to the plugin allowing lower-privileged users to create registration forms and set the default role to administrator This makes it possible for authenticated attackers…

πŸ“… Published: May 10, 2024, 6:44 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:30 a.m.

6.4

CVSS3.1

CVE-2024-4481 - Gutenberg Blocks with AI by Kadence WP <= 3.2.36 - Authenticated (Contributor+) Stored Cross-Site S…

The Gutenberg Blocks with AI by Kadence WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the plugin's blocks in all versions up to, and including, 3.2.36 due to insufficient input sanitization and output escaping on user supplied attributes. This make…

πŸ“… Published: May 10, 2024, 6:44 a.m. πŸ”„ Last Modified: Feb. 7, 2025, 2:27 a.m.
Total resulsts: 342218
Page 9216 of 34,222
Β« previous page Β» next page
Filters