5.4

CVSS3.1

CVE-2024-8854 - Polls CP <= 1.0.75 - Admin+ Stored XSS via Custom Styles

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:31 p.m.

5.4

CVSS3.1

CVE-2024-8851 - Polls CP <= 1.0.75 - Admin+ Stored Cross-Site Scripting

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:31 p.m.

4.8

CVSS3.1

CVE-2024-8759 - Nested Pages <= 3.2.8 - Editor+ Stored XSS

The Nested Pages WordPress plugin before 3.2.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:33 p.m.

6.1

CVSS3.1

CVE-2024-8703 - Z-Downloads < 1.11.6 - Unauthenticated Stored XSS

The Z-Downloads WordPress plugin before 1.11.6 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated visitors to perform Cross-Site Scripting attacks when accessing share URLs.

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 3:41 p.m.

4.8

CVSS3.1

CVE-2024-8702 - Backup Database <= 4.9 - Admin+ Stored XSS

The Backup Database WordPress plugin through 4.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:30 p.m.

4.8

CVSS3.1

CVE-2024-8701 - Event Calendar <= 1.0.4 - Admin+ Stored XSS

The events-calendar WordPress plugin through 1.0.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 3:50 p.m.

7.5

CVSS3.1

CVE-2024-8700 - Event Calendar <= 1.0.4 - Unauthenticated Arbitrary Calendar Deletion

The Event Calendar WordPress plugin through 1.0.4 does not check for authorization on delete actions, allowing unauthenticated users to delete arbitrary calendars.

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: Aug. 27, 2025, noon

7.2

CVSS3.1

CVE-2024-8699 - Z-Downloads < 1.11.5 - Admin+ Arbitrary File Upload

The Z-Downloads WordPress plugin before 1.11.5 does not properly validate files uploaded, allowing high privilege users such as admin to upload arbitrary files on the server even when they should not be allowed to (for example in multisite setup)

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 3:42 p.m.

9.1

CVSS3.1

CVE-2024-8673 - Z-Downloads < 1.11.7 - Admin+ Stored XSS via SVG Upload

The Z-Downloads WordPress plugin before 1.11.7 does not properly validate uploaded files allowing for the uploading of SVGs containing malicious JavaScript.

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: May 28, 2025, 3:42 p.m.

4.8

CVSS3.1

CVE-2024-8670 - Photo Gallery by 10Web < 1.8.29 - Admin+ Stored XSS

The Photo Gallery by 10Web WordPress plugin before 1.8.29 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 8:08 p.m.
Total resulsts: 343168
Page 4785 of 34,317
ยซ previous page ยป next page
Filters