6.4

CVSS3.1

CVE-2024-2923 - Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates L…

The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization a…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

0.0

CVE-2024-4542 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-3548. Reason: This candidate was issued in error. Please use CVE-2024-3548 instead.

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: May 16, 2024, 2:15 p.m.

6.4

CVSS3.1

CVE-2024-4411 - Mihdan: Yandex Turbo Feed <= 1.6.5.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Mihdan: Yandex Turbo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 1.6.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticate…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-4339 - Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) <= 3.14…

The Prime Slider – Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the General widget in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping. This make…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

4.3

CVSS3.1

CVE-2024-4314 - hostel <= 1.1.5.3 - Cross-Site Request Forgery

The Hostel plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.5.3. This is due to missing or incorrect nonce validation when managing rooms. This makes it possible for unauthenticated attackers to create and delete rooms via a forged request g…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-4446 - Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shor…

The Content Views – Post Grid & Filter, Recent Posts, Category Posts, & More (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pagingType’ parameter in all versions up to, and including, 3.7.1 due to insufficient input sanitization and outpu…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3831 - Enter Addons – Ultimate Template Builder for Elementor <= 2.1.5 - Authenticated (Contributor+) Stor…

The Enter Addons – Ultimate Template Builder for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Heading widget in all versions up to, and including, 2.1.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attack…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3595 - Pure Chat – Live Chat Plugin & More! <= 2.22 - Authenticated (Subscriber+) Stored Cross-Site Script…

The Pure Chat – Live Chat Plugin & More! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the purechatwid and purechatwname parameter in all versions up to, and including, 2.22 due to insufficient input sanitization and output escaping. This makes it possible for authenticated …

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

5.4

CVSS3.1

CVE-2024-3722 - Swift Performance Lite <= 2.3.6.18 - Incorrect Authorization to Authenticated (Subscriber+) Setting…

The Swift Performance Lite plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the ajax_handler() function in all versions up to, and including, 2.3.6.18. This makes it possible for authenticated attackers, with subscriber-level access and above, to retrie…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

4.3

CVSS3.1

CVE-2024-4312 - Soccer Engine – Soccer Plugin for WordPress <= 1.12 - Cross-Site Request Forgery

The Soccer Engine – Soccer Plugin for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.12. This is due to missing or incorrect nonce validation when saving match and team settings. This makes it possible for unauthenticated attackers…

📅 Published: May 9, 2024, 8:03 p.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.
Total resulsts: 343944
Page 9394 of 34,395
« previous page » next page
Filters