7.2

CVSS3.1

CVE-2024-13504 - Shared Files – Frontend File Upload Form & Secure File Sharing <= 1.7.42 - Limited Unauthenticated …

The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthentica…

📅 Published: Jan. 31, 2025, 5:22 a.m. 🔄 Last Modified: Jan. 31, 2025, 7:36 p.m.

4.3

CVSS3.1

CVE-2024-13717 - Contact Form and Calls To Action by vcita <= 2.7.1 - Missing Authorization to Authenticated (Subscr…

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_toggle_contact functions in all versions up to, and including, 2.7.1. This makes it possible for authent…

📅 Published: Jan. 31, 2025, 5:22 a.m. 🔄 Last Modified: July 13, 2025, 11:32 a.m.

6.4

CVSS3.1

CVE-2024-11886 - Contact Form and Calls To Action by vcita <= 2.7.1 - Authenticated (Contributor+) Stored Cross-Site…

The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in all versions up to, and including, 2.7.1 due to insufficient input sanitization and output escaping on user supplied attributes. Thi…

📅 Published: Jan. 31, 2025, 5:22 a.m. 🔄 Last Modified: July 12, 2025, 10:15 p.m.

7.2

CVSS3.1

CVE-2025-0809 - Link Fixer <= 3.4 - Unauthenticated Stored Cross-Site Scripting

The Link Fixer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via broken links in all versions up to, and including, 3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that …

📅 Published: Jan. 31, 2025, 5:22 a.m. 🔄 Last Modified: June 27, 2025, 9:26 a.m.

4.3

CVSS3.1

CVE-2024-13216 - HT Event – WordPress Event Manager Plugin for Elementor <= 1.4.7 - Authenticated (Contributor+) Sen…

The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function in /includes/widgets/htevent_sponsor.php. This makes it possible for authenticated attackers, with C…

📅 Published: Jan. 31, 2025, 5:22 a.m. 🔄 Last Modified: Feb. 10, 2025, 10:07 p.m.

5.4

CVSS3.1

CVE-2024-10867 - Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg <= 1.5.9 - Authenti…

The Borderless – Widgets, Elements, Templates and Toolkit for Elementor & Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.5.9 due to insufficient input sanitization and output escaping. This makes it possible f…

📅 Published: Jan. 31, 2025, 4:21 a.m. 🔄 Last Modified: March 25, 2025, 2:35 p.m.

9.8

CVSS3.1

CVE-2025-0493 - MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution <= 4.2.14 - Unauthenticate…

The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the tabname parameter. This makes it possible for unauthenticated attackers to include PHP files on the s…

📅 Published: Jan. 31, 2025, 4:21 a.m. 🔄 Last Modified: May 23, 2025, 4:10 p.m.

6.4

CVSS3.1

CVE-2025-0507 - Ticketmeo – Sell Tickets – Event Ticketing <= 2.3.6 - Authenticated (Contributor+) Stored Cross-Sit…

The Ticketmeo – Sell Tickets – Event Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for…

📅 Published: Jan. 31, 2025, 4:21 a.m. 🔄 Last Modified: Feb. 10, 2025, 10:07 p.m.

6.1

CVSS3.1

CVE-2025-0470 - Forminator <= 1.38.2 - Reflected Cross-Site Scripting via Title Parameter

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the title parameter in all versions up to, and including, 1.38.2 due to insufficient input sanitization and output escaping. This makes it possible for un…

📅 Published: Jan. 31, 2025, 3:21 a.m. 🔄 Last Modified: May 23, 2025, 4:14 p.m.

6.4

CVSS3.1

CVE-2024-13463 - SeatReg <= 1.56.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The SeatReg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'seatreg' shortcode in all versions up to, and including, 1.56.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

📅 Published: Jan. 31, 2025, 3:21 a.m. 🔄 Last Modified: July 12, 2025, 10:23 p.m.
Total resulsts: 343040
Page 6279 of 34,304
« previous page » next page
Filters