5.4

CVSS3.1

CVE-2024-9599 - Popup Box < 4.7.8 - Admin+ Stored XSS

The Popup Box WordPress plugin before 4.7.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 8:06 p.m.

6.5

CVSS3.1

CVE-2024-9450 - Free Booking Plugin for Hotels, Restaurants and Car Rentals โ€“ eaSYNC Booking < 1.3.15 - Subscriber+โ€ฆ

The Free Booking Plugin for Hotels, Restaurants and Car Rentals WordPress plugin before 1.3.15 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in subscriber change them via a CSRF attack

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: Jan. 23, 2026, 7:32 p.m.

4.8

CVSS3.1

CVE-2024-9390 - RegistrationMagic < 6.0.2.1 - Stored XSS

The RegistrationMagic WordPress plugin before 6.0.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 8:07 p.m.

5.4

CVSS3.1

CVE-2024-9238 - AVIF & SVG Uploader <= 1.1.0 - Author+ Stored XSS via SVG Uplaod

The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:31 p.m.

4.8

CVSS3.1

CVE-2024-9236 - Team Members Showcase < 4.4.2 - Editor+ Stored XSS

The Team WordPress plugin before 4.4.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:43 p.m.

4.3

CVSS3.1

CVE-2024-9233 - GS Logo Slider < 3.7.1 - Settings Update via Cross-Site Request Forgery

The Logo Slider WordPress plugin before 3.7.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 8:07 p.m.

4.8

CVSS3.1

CVE-2024-9227 - PowerPress Podcasting < 11.9.18 - Author+ XSS

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.9.18 does not sanitise and escape some of its settings when adding a podcast, which could allow admin users to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 5, 2025, 2:21 p.m.

4.8

CVSS3.1

CVE-2024-9182 - Maspik - Advanced Spam protection < 2.1.3 - Admin+ Stored XSS

The Maspik WordPress plugin before 2.1.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed.

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 12, 2025, 4:36 p.m.

5.4

CVSS3.1

CVE-2024-8854 - Polls CP <= 1.0.75 - Admin+ Stored XSS via Custom Styles

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:31 p.m.

5.4

CVSS3.1

CVE-2024-8851 - Polls CP <= 1.0.75 - Admin+ Stored Cross-Site Scripting

The Polls CP WordPress plugin before 1.0.77 does not sanitise and escape some of its poll settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multi site setup).

๐Ÿ“… Published: May 15, 2025, 8:07 p.m. ๐Ÿ”„ Last Modified: June 4, 2025, 4:31 p.m.
Total resulsts: 346547
Page 5122 of 34,655
ยซ previous page ยป next page
Filters