8.6

CVSS3.1

CVE-2024-12542 - linkID <= 0.1.2 - Missing Authorization to Unauthenticated Sensitive Information Exposure

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings and predefined variab…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 5:16 p.m.

9.8

CVSS3.1

CVE-2024-11642 - Post Grid Master <= 3.4.12 - Missing Authorization to Unauthenticated Local PHP File Inclusion

The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the 'locate_template' function. This makes it pos…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 7:19 p.m.

4.3

CVSS3.1

CVE-2024-12616 - Bitly's WordPress Plugin <= 2.7.3 - Missing Authorization to Authenticated (Subscriber+) Settings U…

The Bitly&#039;s WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and including, 2.7.3. This makes it possible for authenticated attackers, with Subscriber-level access and above…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

6.4

CVSS3.1

CVE-2024-12491 - SimplyRETS Real Estate IDX <= 2.11.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and including, 2.11.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible fo…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 7:20 p.m.

6.4

CVSS3.1

CVE-2024-12515 - Muslim Prayer Time-Salah/Iqamah <= 1.8.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, 1.8.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contrib…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-12819 - Searchie <= 1.17.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortcode in all versions up to, and including, 1.17.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated a…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 5:05 p.m.

8.8

CVSS3.1

CVE-2024-12848 - SKT Page Builder <= 4.6 - Authenticated (Subscriber+) Arbitrary File Upload

The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the 'addLibraryByArchive' function in all versions up to, and including, 4.6. This makes it possible for authenticated attackers, with subscriber-level access and above, to upload …

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 5:05 p.m.

6.1

CVSS3.1

CVE-2024-11686 - WhatsApp click to chat <= 3.0.4 - Reflected Cross-Site Scripting

The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inj…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 5:02 p.m.

6.1

CVSS3.1

CVE-2024-11815 - Pósturinn\'s Shipping with WooCommerce <= 1.3.1 - Reflected Cross-Site Scripting

The Pósturinn\&#039;s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the printed_marked and nonprinted_marked parameters in all versions up to, and including, 1.3.1 due to insufficient input sanitization and output escaping. This makes it possible…

📅 Published: Jan. 9, 2025, 11:11 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-11907 - Skyword API Plugin <= 2.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_iframe' shortcode in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Jan. 9, 2025, 11:10 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.
Total resulsts: 343838
Page 6675 of 34,384
« previous page » next page
Filters