5.4

CVSS3.1

CVE-2024-2017 - Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.7.8 - Missing Authorization to Authent…

The Countdown, Coming Soon, Maintenance – Countdown & Clock plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the conditionsRow and switchCountdown functions in all versions up to, and including, 2.7.8. This makes it possible for authenticated attackers,…

📅 Published: June 6, 2024, 2:38 a.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

6.4

CVSS3.1

CVE-2024-4705 - Testimonials Widget <= 4.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via testimonials…

The Testimonials Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's testimonials shortcode in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authentica…

📅 Published: June 6, 2024, 2:03 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

8.8

CVSS3.1

CVE-2024-5179 - Cowidgets – Elementor Addons <= 1.1.2 - Authenticated (Contributor+) Local File Inclusion

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.2 via the 'item_style' and 'style' parameters. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute ar…

📅 Published: June 6, 2024, 2:03 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-2350 - Clever Addons for Elementor <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via…

The Clever Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the CAFE Icon, CAFE Team Member, and CAFE Slider widgets in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping. This makes it possible for authentic…

📅 Published: June 6, 2024, 2:03 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

6.4

CVSS3.1

CVE-2024-5224 - Easy Social Like Box – Popup – Sidebar Widget <= 4.0 - Authenticated (Contributor+) Stored Cross-Si…

The Easy Social Like Box – Popup – Sidebar Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cardoza_facebook_like_box' shortcode in all versions up to, and including, 4.0 due to insufficient input sanitization and output escaping on user supplied attributes…

📅 Published: June 6, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 7:21 p.m.

8.1

CVSS3.1

CVE-2023-6966 - The Moneytizer <= 9.6.3 - Missing Authorization via multiple AJAX actions

The The Moneytizer plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to a missing capability check on multiple AJAX functions in the /core/core_ajax.php file in all versions up to, and including, 9.6.3. This makes it possible for authentic…

📅 Published: June 6, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 6:18 p.m.

6.4

CVSS3.1

CVE-2024-5001 - Image Hover Effects for Elementor with Lightbox and Flipbox <= 3.0.2 - Authenticated (Contributor+)…

The Image Hover Effects for Elementor with Lightbox and Flipbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '_id', 'oxi_addons_f_title_tag', and 'content_description_tag' parameters in all versions up to, and including, 3.0.2 due to insufficient input sanitization and …

📅 Published: June 6, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.5

CVSS3.1

CVE-2024-4194 - Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Execution

The The Album and Image Gallery plus Lightbox plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This make…

📅 Published: June 6, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 6:21 p.m.

6.1

CVSS3.1

CVE-2023-6956 - EasyAzon – Amazon Associates Affiliate Plugin <= 5.1.0 - Reflected Cross-Site Scripting via easyazo…

The EasyAzon – Amazon Associates Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘easyazon-cloaking-locale’ parameter in all versions up to, and including, 5.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unau…

📅 Published: June 6, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 4:47 p.m.

5.3

CVSS3.1

CVE-2024-0910 - Restrict for Elementor <= 1.0.7 - Protection Mechanism Bypass

The Restrict for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.7 due to improper restrictions on hidden data that make it accessible through the REST API. This makes it possible for unauthenticated attackers to extract poten…

📅 Published: June 6, 2024, 2:02 a.m. 🔄 Last Modified: April 8, 2026, 5:17 p.m.
Total resulsts: 349182
Page 9572 of 34,919
« previous page » next page
Filters