4.8

CVSS3.1

CVE-2024-6798 - DL Verification <= 1.2 - Admin+ Stored XSS

The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 9, 2025, 8:12 p.m.

4.8

CVSS3.1

CVE-2024-6797 - DL Robots.txt <= 1.2 - Admin+ Stored XSS

The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: Jan. 2, 2026, 9:07 p.m.

8.1

CVSS3.1

CVE-2024-6719 - Offload Videos โ€“ Bunny.net, AWS S3 <= 1.0.1 Subscriber+ CSRF

The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: Jan. 5, 2026, 6:11 p.m.

5.4

CVSS3.1

CVE-2024-6718 - PVN Auth Popup <= 1.0.0 - Contributor+ XSS via Shortcode

The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: May 27, 2025, 8 p.m.

4.8

CVSS3.1

CVE-2024-6713 - PVN Auth Popup <= 1.0.0 - Admin+ Stored XSS

The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 11, 2025, 4:56 p.m.

6.1

CVSS3.1

CVE-2024-6712 - MapFig Studio <= 0.2.1 - Stored XSS via CSRF

The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 11, 2025, 4:58 p.m.

4.8

CVSS3.1

CVE-2024-6708 - Profile Builder <= 3.12.0 - Admin+ Stored Cross Site Scripting

The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 8:09 p.m.

4.8

CVSS3.1

CVE-2024-6693 - WP Content Copy Protection & No Right Click (premium) <= 15.0 - Admin+ Stored XSS

The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 11, 2025, 5:04 p.m.

6.1

CVSS3.1

CVE-2024-6690 - WP Content Copy Protection & No Right Click (premium) < 15.3 - Open Redirect

The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 11, 2025, 2:59 p.m.

5.4

CVSS3.1

CVE-2024-6668 - profilepro <= 1.3 - Subscriber+ Stored Cross Site Scripting

The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 8:10 p.m.
Total resulsts: 343168
Page 4789 of 34,317
ยซ previous page ยป next page
Filters