5.4

CVSS3.1

CVE-2024-5475 - Responsive video embed < 0.5.1 - Contributor+ Stored XSS

The Responsive video embed WordPress plugin before 0.5.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.

πŸ“… Published: June 20, 2024, 6 a.m. πŸ”„ Last Modified: June 17, 2025, 6:57 p.m.

7.5

CVSS3.1

CVE-2024-4565 - Advanced Custom Fields < 6.3 - Contributor+ Custom Field Access

The Advanced Custom Fields (ACF) WordPress plugin before 6.3, Advanced Custom Fields Pro WordPress plugin before 6.3 allows you to display custom field values for any post via shortcode without checking for the correct access

πŸ“… Published: June 20, 2024, 6 a.m. πŸ”„ Last Modified: Aug. 27, 2025, noon

6.9

CVSS4.0

CVE-2024-6113 - itsourcecode Monbela Tourist Inn Online Reservation System login.php sql injection

A vulnerability was found in itsourcecode Monbela Tourist Inn Online Reservation System 1.0. It has been rated as critical. This issue affects some unknown processing of the file login.php. The manipulation of the argument email leads to sql injection. The attack may be initiated remotely. The iden…

πŸ“… Published: June 20, 2024, 5:18 a.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:48 a.m.

6.4

CVSS3.1

CVE-2024-5686 - WPZOOM Addons for Elementor (Templates, Widgets) <= 1.1.38 - Authenticated (Contributor+) Stored Cr…

The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜url’ attribute within the plugin's Team Members widget in all versions up to, and including, 1.1.38 due to insufficient input sanitization and output escaping. This makes …

πŸ“… Published: June 20, 2024, 3:37 a.m. πŸ”„ Last Modified: April 8, 2026, 7:22 p.m.

6.5

CVSS3.1

CVE-2024-4390 - Depicter <= 3.0.2 - Authenticated (Contributor+) Arbitrary Nonce Generation

The Slider and Carousel slider by Depicter plugin for WordPress is vulnerable to Arbitrary Nonce Generation in all versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with contributor access and above, to generate a valid nonce for any WordPress action/function.…

πŸ“… Published: June 20, 2024, 3:37 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

8.8

CVSS3.1

CVE-2024-5605 - Media Library Assistant <= 3.16 - Authenticated (Contributor+) SQL Injection via order Parameter

The Media Library Assistant plugin for WordPress is vulnerable to time-based SQL Injection via the β€˜order’ parameter within the mla_tag_cloud Shortcode in all versions up to, and including, 3.16 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the ex…

πŸ“… Published: June 20, 2024, 3:37 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

6.5

CVSS3.1

CVE-2024-5213 - Exposure of Sensitive Information in mintplex-labs/anything-llm

In mintplex-labs/anything-llm versions up to and including 1.5.3, an issue was discovered where the password hash of a user is returned in the response after login (`POST /api/request-token`) and after account creations (`POST /api/admin/users/new`). This exposure occurs because the entire User obj…

πŸ“… Published: June 20, 2024, 2:15 a.m. πŸ”„ Last Modified: Oct. 15, 2025, 1:15 p.m.

8.8

CVSS3.1

CVE-2024-3562 - Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) PHP Code Injection via Loop Custom Field

The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the eval() function. This makes it possible for authenticated att…

πŸ“… Published: June 20, 2024, 2:08 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-1168 - SEOPress – On-site SEO <= 7.9 - Authenticated(Contributor+) Stored Cross-Site Scripting via Social …

The SEOPress – On-site SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's social image URL in all versions up to, and including, 7.9 due to insufficient input sanitization and output escaping on user supplied image URLs. This makes it possible for authenticated a…

πŸ“… Published: June 20, 2024, 2:08 a.m. πŸ”„ Last Modified: April 8, 2026, 7:20 p.m.

8.8

CVSS3.1

CVE-2024-3561 - Custom Field Suite <= 2.6.7 - Authenticated (Contributor+) SQL Injection via Term Custom Field

The Custom Field Suite plugin for WordPress is vulnerable to SQL Injection via the the 'Term' custom field in all versions up to, and including, 2.6.7 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo…

πŸ“… Published: June 20, 2024, 2:08 a.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.
Total resulsts: 349182
Page 9378 of 34,919
Β« previous page Β» next page
Filters