6.4

CVSS3.1

CVE-2024-3923 - Beaver Builder – WordPress Page Builder <= 2.8.1.1 - Authenticated (Contributor+) Stored Cross-Site…

The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the link_target parameter in all versions up to, and including, 2.8.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, w…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

6.4

CVSS3.1

CVE-2024-3990 - HT Mega – Absolute Addons For Elementor <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site S…

The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Tooltip & Popover Widget in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible f…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

9.8

CVSS3.1

CVE-2024-3806 - Porto <= 7.1.0 - Unauthenticated Local File Inclusion via porto_ajax_posts

The Porto theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 7.1.0 via the 'porto_ajax_posts' function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in t…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-1230 - SimpleShop <= 2.10.0 - Cross-Site Request Forgery

The SimpleShop plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10.0. This is due to missing or incorrect nonce validation on the maybe_disconnect_simpleshop function. This makes it possible for unauthenticated attackers to disconnect the site…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-4335 - Rank Math SEO with AI Best SEO Tools <= 1.0.217 - Authenticated (Contributor+) Stored Cross-Site Sc…

The Rank Math SEO with AI Best SEO Tools plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜textAlign’ parameter in versions up to, and including, 1.0.217 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with con…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

4.3

CVSS3.1

CVE-2024-4103 - ADFO – Custom data in admin dashboard <= 1.9.0 - Cross-Site Request Forgery

The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9.0. This is due to missing or incorrect nonce validation on several functions hooked via the controller() function. This makes it possible for unauthen…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.1

CVSS3.1

CVE-2024-4441 - XML Sitemap & Google News <= 5.4.8 - Unauthenticated Local File Inclusion

The XML Sitemap & Google News plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.4.8 via the 'feed' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-3915 - Swift Framework <= 2.7.31 - Missing Authorization to Unauthenticated Arbitrary Content Update

The Swift Framework plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sf_edit_directory_item() function in all versions up to, and including, 2.7.31. This makes it possible for unauthenticated attackers to update arbitrary posts with ar…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-2923 - Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates L…

The Magical Addons For Elementor ( Header Footer Builder, Free Elementor Widgets, Elementor Templates Library ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's text effect widget in all versions up to, and including, 1.1.37 due to insufficient input sanitization a…

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: April 8, 2026, 6:21 p.m.

0.0

CVE-2024-4542 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-3548. Reason: This candidate was issued in error. Please use CVE-2024-3548 instead.

πŸ“… Published: May 9, 2024, 8:03 p.m. πŸ”„ Last Modified: May 16, 2024, 2:15 p.m.
Total resulsts: 349182
Page 9917 of 34,919
Β« previous page Β» next page
Filters