4.3
CVE-2024-34371 - WordPress Login with phone number plugin <= 1.7.18 - Broken Access Control vulnerability
Missing Authorization vulnerability in Hamid Alinia Login with phone number login-with-phone-number.This issue affects Login with phone number: from n/a through <= 1.7.18.
5.3
CVE-2024-34372 - WordPress Post Grid Master plugin <= 3.4.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in AddonMaster Post Grid Master.This issue affects Post Grid Master: from n/a through 3.4.7.
4.3
CVE-2024-34377 - WordPress Video Gallery β Api Gallery, YouTube and Vimeo, Link Gallery plugin <= 1.5.3 - Broken Accβ¦
Missing Authorization vulnerability in A WP Life Video Gallery β Api Gallery, YouTube and Vimeo, Link Gallery.This issue affects Video Gallery β Api Gallery, YouTube and Vimeo, Link Gallery: from n/a through 1.5.3.
8.6
CVE-2024-34378 - WordPress LeadConnector plugin <= 1.7 - API Broken Access Control vulnerability
Missing Authorization vulnerability in LeadConnector.This issue affects LeadConnector: from n/a through 1.7.
4.3
CVE-2024-34387 - WordPress WP Post Author plugin <= 3.6.4 - Rating Value Manipulation vulnerability
Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
4.3
CVE-2024-34389 - WordPress WP Post Author plugin <= 3.6.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in AF themes WP Post Author.This issue affects WP Post Author: from n/a through 3.6.4.
5.9
CVE-2024-34366 - WordPress AltText.ai plugin <= 1.3.4 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in AltText.Ai Download Alt Text AI allows Stored XSS.This issue affects Download Alt Text AI: from n/a through 1.3.4.
7.1
CVE-2024-34369 - WordPress Web Push Notifications β Webpushr plugin <= 4.35.0 - Cross Site Scripting (XSS) vulnerabiβ¦
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webpushr Web Push Notifications Webpushr allows Reflected XSS.This issue affects Webpushr: from n/a through 4.35.0.
7.6
CVE-2024-3661 - DHCP routing options can manipulate interface-based VPN traffic
DHCP can add routes to a clientβs routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify neβ¦
6.5
CVE-2024-34373 - WordPress The Plus Addons for Elementor plugin <= 5.4.2 - Cross Site Scripting (XSS) vulnerability
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in POSIMYTH The Plus Addons for Elementor Page Builder Lite the-plus-addons-for-elementor-page-builder.This issue affects The Plus Addons for Elementor Page Builder Lite: from n/a through <= 5.4.2.