5.3
CVE-2024-32685 - WordPress WP Ultimate Review plugin <= 2.2.5 - Review Score Manipulation vulnerability
Client-Side Enforcement of Server-Side Security vulnerability in Wpmet Wp Ultimate Review allows Functionality Bypass.This issue affects Wp Ultimate Review: from n/a through 2.2.5.
8.8
CVE-2024-32680 - WordPress HUSKY plugin <= 1.3.5.2 - Remote Code Execution (RCE) vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY β Products Filter for WooCommerce (formerly WOOF) allows Using Malicious Files, Code Inclusion.This issue affects HUSKY β Productβ¦
8.1
CVE-2024-32523 - WordPress Mailster plugin <= 4.0.6 - Unauthenticated Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in EverPress Mailster mailster.This issue affects Mailster: from n/a through <= 4.0.6.
5.3
CVE-2024-32521 - WordPress Zero Spam for WordPress plugin <= 5.5.6 - Bypass Spam Protection vulnerability
Client-Side Enforcement of Server-Side Security vulnerability in Highfivery LLC Zero Spam allows Removing Important Client Functionality.This issue affects Zero Spam: from n/a through 5.5.6.
5.3
CVE-2024-32512 - WordPress weForms plugin <= 1.6.20 - Form Submission Restriction Bypass vulnerability
Client-Side Enforcement of Server-Side Security vulnerability in weForms allows Removing Important Client Functionality.This issue affects weForms: from n/a through 1.6.20.
9.8
CVE-2024-32511 - WordPress Simple Registration for WooCommerce plugin <= 1.5.6 - Unauthenticated Privilege Escalatioβ¦
Improper Privilege Management vulnerability in Astoundify Simple Registration for WooCommerce allows Privilege Escalation.This issue affects Simple Registration for WooCommerce: from n/a through 1.5.6.
8.8
CVE-2024-32507 - WordPress Login with phone number plugin <= 1.7.16 - Privilege Escalation vulnerability
Incorrect Privilege Assignment vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.16.
8.5
CVE-2024-31300 - WordPress Easy Social Share Buttons plugin <= 9.4 - Local File Inclusion vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in appscreo Easy Social Share Buttons allows PHP Local File Inclusion.This issue affects Easy Social Share Buttons: from n/a through 9.4.
9.8
CVE-2024-31290 - WordPress Demo My WordPress plugin <= 1.0.9.1 - Unauthenticated Privilege Escalation vulnerability
Improper Privilege Management vulnerability in CodeRevolution Demo My WordPress allows Privilege Escalation.This issue affects Demo My WordPress: from n/a through 1.0.9.1.
6.3
CVE-2024-31281 - WordPress Church Admin plugin <= 4.1.6 - Broken Access Control vulnerability
Missing Authorization vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.1.6.