9.9

CVSS3.1

CVE-2024-3592 - Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress <= 9.0.1 - Authenticated (…

The Quiz And Survey Master – Best Quiz, Exam and Survey Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'question_id' parameter in all versions up to, and including, 9.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation…

📅 Published: June 7, 2024, 5:33 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

4.3

CVSS3.1

CVE-2023-6491 - Strong Testimonials <= 3.1.12 - Authenticated(Contributor+) Improper Authorization to Views Modific…

The Strong Testimonials plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the wpmtst_save_view_sticky function in all versions up to, and including, 3.1.12. This makes it possible for authenticated attackers, with contributor access and a…

📅 Published: June 7, 2024, 5:33 a.m. 🔄 Last Modified: April 8, 2026, 7:18 p.m.

6.4

CVSS3.1

CVE-2024-4354 - TablePress – Tables in WordPress made easy <= 2.3 - Authenticated (Author+) Server-Side Request For…

The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 2.3 via the get_files_to_import() function. This makes it possible for authenticated attackers, with author-level access and above, to make web requ…

📅 Published: June 7, 2024, 5:33 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-4042 - Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel - Combo Blocks <…

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' attribute of the menu-wrap-item block in all versions up to, and including, 2.2.80 due to insufficient input saniti…

📅 Published: June 7, 2024, 5:33 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

7.2

CVSS3.1

CVE-2024-4902 - Tutor LMS – eLearning and online course solution <= 2.7.1 -Authenticated (Administrator+) SQL Injec…

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to time-based SQL Injection via the ‘course_id’ parameter in all versions up to, and including, 2.7.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existin…

📅 Published: June 7, 2024, 4:33 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-5640 - Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14…

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ attribute within the Pacific widget in all versions up to, and including, 3.14.7 due to insufficient input sanitization and …

📅 Published: June 7, 2024, 4:33 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-5612 - Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders <= …

The Essential Addons for Elementor Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘eael_lightbox_open_btn_icon’ parameter within the Lightbox & Modal widget in all versions up to, and including, 5.8.15 due to insufficient input sanitization and output escaping. This m…

📅 Published: June 7, 2024, 4:33 a.m. 🔄 Last Modified: April 8, 2026, 6:22 p.m.

6.5

CVSS3.1

CVE-2024-36082 -

SQL injection vulnerability in Music Store - WordPress eCommerce versions prior to 1.1.14 allows a remote authenticated attacker with an administrative privilege to execute arbitrary SQL commands. Information stored in the database may be obtained or altered by the attacker.

📅 Published: June 7, 2024, 3:42 a.m. 🔄 Last Modified: Nov. 21, 2024, 9:21 a.m.

9.8

CVSS3.1

CVE-2024-37385 -

Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 on Windows allows command injection via im_convert_path and im_identify_path. NOTE: this issue exists because of an incomplete fix for CVE-2020-12641.

📅 Published: June 7, 2024, 3:24 a.m. 🔄 Last Modified: Feb. 6, 2026, 5:48 p.m.

6.4

CVSS3.1

CVE-2024-1988 - Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks <…

The Post Grid, Form Maker, Popup Maker, WooCommerce Blocks, Post Blocks, Post Carousel – Combo Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' attribute in blocks in all versions up to, and including, 2.2.80 due to insufficient input sanitization and output es…

📅 Published: June 7, 2024, 3:21 a.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.
Total resulsts: 346120
Page 9246 of 34,612
« previous page » next page
Filters