5.3

CVSS4.0

CVE-2024-4686 - Campcodes Complete Web-Based School Management System emarks_range_grade_update_form.php cross site…

A vulnerability was found in Campcodes Complete Web-Based School Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file /view/emarks_range_grade_update_form.php. The manipulation of the argument grade leads to cross site scripting. The attack…

📅 Published: May 9, 2024, 8:31 p.m. 🔄 Last Modified: Feb. 19, 2025, 6:39 p.m.

8.8

CVSS3.1

CVE-2024-3808 - Porto Theme - Functionality <= 3.1.0 - Authenticated (Contributor+) Local File Inclusion via Shortc…

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.1.0 via the 'porto_portfolios' shortcode 'portfolio_layout' attribute. This makes it possible for authenticated attackers, with contributor-level and above permissions,…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

7.2

CVSS3.1

CVE-2024-2290 - Advanced Ads – Ad Manager & AdSense <= 1.52.1 - Authenticated (Admin+) PHP Object Injection

The Advanced Ads plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.52.1 via deserialization of untrusted input in the 'placement_slug' parameter. This makes it possible for authenticated attackers to inject a PHP Object. No POP chain is present in th…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

8.8

CVSS3.1

CVE-2024-3809 - Porto Theme - Functionality <= 3.0.9 - Authenticated (Contributor+) Local File Inclusion via Post M…

The Porto Theme - Functionality plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.0.9 via the 'slideshow_type' post meta. This makes it possible for authenticated attackers, with contributor-level and above permissions, to include and execute arbitra…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

8.8

CVSS3.1

CVE-2024-4397 - LearnPress – WordPress LMS Plugin <= 4.2.6.5 - Authenticated (Instructor+) Arbitrary File Upload

The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_post_materials' function in versions up to, and including, 4.2.6.5. This makes it possible for authenticated attackers, with Instructor-level permissio…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.1

CVSS3.1

CVE-2024-4104 - ADFO – Custom data in admin dashboard <= 1.9.0 - Reflected Cross-Site Scripting

The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dbp_id' parameter in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to i…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.5

CVSS3.1

CVE-2024-4038 - Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro <= 5.3.1 - Unauthenticated Arbitr…

The The Back In Stock Notifier for WooCommerce | WooCommerce Waitlist Pro plugin for WordPress for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.3.1. This is due to the plugin for WordPress allowing users to execute an action that does not properly…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-2785 - The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting v…

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Age Gate widget in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated at…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

4.3

CVSS3.1

CVE-2024-1467 - Starter Templates — Elementor, WordPress & Beaver Builder Templates <= 4.1.6 - Authenticated (Contr…

The Starter Templates — Elementor, WordPress & Beaver Builder Templates plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.1.6 via the ai_api_request(). This makes it possible for authenticated attackers, with contributor-level access and above…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

4.3

CVSS3.1

CVE-2024-4463 - Squelch Tabs and Accordions Shortcodes <= 0.4.7 - Cross-Site Request Forgery

The Squelch Tabs and Accordions Shortcodes plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.4.7. This is due to missing or incorrect nonce validation when saving plugin settings. This makes it possible for unauthenticated attackers to modify p…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.
Total resulsts: 343948
Page 9392 of 34,395
« previous page » next page
Filters