6.4

CVSS3.1

CVE-2024-5601 - Create by Mediavine <= 1.9.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Schema …

The Create by Mediavine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Schema Meta shortcode in all versions up to, and including, 1.9.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticat…

πŸ“… Published: June 27, 2024, 7:44 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

7.7

CVSS3.1

CVE-2024-22232 - Specially crafted url can be created which leads to a directory traversal in the salt file server

A specially crafted url can be created which leads to a directory traversal in the salt file server. A malicious user can read an arbitrary file from a Salt master’s filesystem.

πŸ“… Published: June 27, 2024, 6:54 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5

CVSS3.1

CVE-2024-22231 - Syndic cache directory creation is vulnerable to a directory traversal attack

Syndic cache directory creation is vulnerable to a directory traversal attack in salt project which can leadΒ a malicious attacker to create an arbitrary directory on a Salt master.

πŸ“… Published: June 27, 2024, 6:51 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-4704 - Contact Form 7 < 5.9.5 - Unauthenticated Open Redirect

The Contact Form 7 WordPress plugin before 5.9.5 has an open redirect that allows an attacker to utilize a false URL and redirect to the URL of their choosing.

πŸ“… Published: June 27, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

4.8

CVSS3.1

CVE-2024-4664 - WP Chat App < 3.6.5 - Admin+ Stored XSS

The WP Chat App WordPress plugin before 3.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admins to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

πŸ“… Published: June 27, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:43 a.m.

5.4

CVSS3.1

CVE-2024-3111 - H5P < 1.15.8 - Contributor+ Stored XSS

The Interactive Content WordPress plugin before 1.15.8 does not validate uploads which could allow a Contributors and above to update malicious SVG files, leading to Stored Cross-Site Scripting issues

πŸ“… Published: June 27, 2024, 6 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:28 a.m.

4.3

CVSS3.1

CVE-2024-1330 - Kadence Blocks Pro < 2.3.8 - Contributor+ Arbitrary Option Access

The kadence-blocks-pro WordPress plugin before 2.3.8 does not prevent users with at least the contributor role using some of its shortcode's functionalities to leak arbitrary options from the database.

πŸ“… Published: June 27, 2024, 6 a.m. πŸ”„ Last Modified: Sept. 15, 2025, 8:03 p.m.

5.4

CVSS3.1

CVE-2024-6283 - DethemeKit For Elementor <= 2.1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via UR…

The DethemeKit For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL parameter of the De Gallery widget in all versions up to and including 2.1.5 due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible for …

πŸ“… Published: June 27, 2024, 4:38 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.4

CVSS3.1

CVE-2024-4570 - Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ parameter in versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level perm…

πŸ“… Published: June 27, 2024, 4:04 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-4569 - Elementor Addon Elements <= 1.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ parameter in versions up to, and including, 1.13.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level perm…

πŸ“… Published: June 27, 2024, 4:04 a.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.
Total resulsts: 349182
Page 9318 of 34,919
Β« previous page Β» next page
Filters