6.4

CVSS3.1

CVE-2024-4567 - Themify Shortcodes <= 2.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via themify_…

The Themify Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themify_button shortcode in all versions up to, and including, 2.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentic…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

4.3

CVSS3.1

CVE-2024-4082 - Joli FAQ SEO – WordPress FAQ Plugin <= 1.3.2 - Cross-Site Request Forgery

The Joli FAQ SEO – WordPress FAQ Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce validation when saving settings. This makes it possible for unauthenticated attackers to change the plugin'…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

9.8

CVSS3.1

CVE-2024-3070 - Last Viewed Posts by WPBeginner <= 1.0.0 - Unauthenticated PHP Object Injection

The Last Viewed Posts by WPBeginner plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input from the LastViewedPosts Cookie. This makes it possible for unauthenticated attackers to inject a PHP Object. No known PO…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-0445 - The Plus Addons for Elementor <= 5.4.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's element attributes in all versions up to, and including, 5.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers with con…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 7:19 p.m.

4.4

CVSS3.1

CVE-2024-2846 - Visual Footer Credit Remover <= 1.2 - Authenticated (Admin+) Stored Cross-Site Scripting

The Visual Footer Credit Remover plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'selector' parameter in all versions up to, and including, 2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3923 - Beaver Builder – WordPress Page Builder <= 2.8.1.1 - Authenticated (Contributor+) Stored Cross-Site…

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_target parameter in all versions up to, and including, 2.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3990 - HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site S…

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

9.8

CVSS3.1

CVE-2024-3806 - Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in t…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

4.3

CVSS3.1

CVE-2024-1230 - SimpleShop <= 2.10.0 - Cross-Site Request Forgery

The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or incorrect nonce validation on the maybe_disconnect_simpleshop function. This makes it possible for unauthenticated attackers to disconnect the site…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:20 p.m.

6.4

CVSS3.1

CVE-2024-4335 - Rank Math SEO with AI Best SEO Tools <= 1.0.217 - Authenticated (Contributor+) Stored Cross-Site Sc…

The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜textAlign’ parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with con…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.
Total resulsts: 343947
Page 9393 of 34,395
Β« previous page Β» next page
Filters