6.5
CVE-2024-34571 - WordPress Himalayas theme <= 1.3.0 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGrill Himalayas allows Stored XSS.This issue affects Himalayas: from n/a through 1.3.0.
5.4
CVE-2024-4135 - WP Latest Posts <= 5.0.7 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
The WP Latest Posts plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.7. This is due to the plugin allowing users to execute an action that does not properly validate a user-supplied value prior to using that value in a call to do_shortcodโฆ
6.4
CVE-2024-4281 - Link Library <= 7.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via link-library โฆ
The Link Library plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'link-library' shortcode in all versions up to, and including, 7.6.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated โฆ
6.5
CVE-2024-34572 - WordPress Fancy Elementor Flipbox plugin <= 2.4.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemePrix Fancy Elementor Flipbox fancy-elementor-flipbox allows Stored XSS.This issue affects Fancy Elementor Flipbox: from n/a through 2.4.2.
6.5
CVE-2024-34573 - WordPress Pootle Pagebuilder plugin <= 5.7.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pootlepress Pootle Pagebuilder โ WordPress Page builder allows Stored XSS.This issue affects Pootle Pagebuilder โ WordPress Page builder: from n/a through 5.7.1.
5.9
CVE-2024-34574 - WordPress Table Maker plugin <= 1.9.1 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wpsoul Table Maker allows Stored XSS.This issue affects Table Maker: from n/a through 1.9.1.
6.5
CVE-2023-41651 - WordPress Multi-column Tag Map plugin <= 17.0.26 - Broken Access Control vulnerability
Missing Authorization vulnerability in Multi-column Tag Map.This issue affects Multi-column Tag Map: from n/a through 17.0.26.
6.5
CVE-2024-1076 - SSL Zen <= 4.5.3 - Unauthenticated Private Keys Access
The SSL Zen WordPress plugin before 4.6.0 does not properly prevent directory listing of the private keys folder, as it only relies on the use of .htaccess to prevent visitors from accessing the site's generated private keys, which allows an attacker to read them if the site runs on a server who dโฆ
6.4
CVE-2024-3494 - Mesmerize Companion <= 1.6.148 - Authenticated (Contributor+) Stored Cross-Site Scripting via mesmeโฆ
The Mesmerize Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mesmerize_contact_form' shortcode in all versions up to, and including, 1.6.148 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible โฆ
6.5
CVE-2024-22266 - VMware Avi Load Balancer updates address multiple vulnerabilities
ย VMware Avi Load Balancer contains an information disclosure vulnerability.ย A malicious actor with access to the system logs can view cloud connectionย credentials in plaintext.