6.1
CVE-2024-9208 - Enable Accessibility <= 1.4.1 - Reflected Cross-Site Scripting
The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.1. This makes it possible for unauthenticated attackers to inject arbitrโฆ
4.3
CVE-2024-12327 - LazyLoad Background Images <= 1.0.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Sโฆ
The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pblzbg_save_settings() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level acceโฆ
6.5
CVE-2024-11496 - Infility Global <= 2.9.8 - Authenticated (Subscriber+) Missing Authorization to Plugin Options Updaโฆ
The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_ajax function in all versions up to, and including, 2.9.8. This makes it possible for authenticated attackers, with Subscriber-level access and above,โฆ
5.3
CVE-2024-12159 - Optimize Your Campaigns โ Google Shopping โ Google Ads โ Google Adwords <= 3.1 - Information Exposuโฆ
The Optimize Your Campaigns โ Google Shopping โ Google Ads โ Google Adwords plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1 due to the print_php_information.php being publicly accessible. This makes it possible for unauthenticated attackers to exโฆ
6.1
CVE-2024-12256 - Simple Video Management System <= 1.0.4 - Reflected Cross-Site Scripting
The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analytics_video' parameter in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers toโฆ
5.3
CVE-2024-12176 - WordLift โ AI powered SEO โ Schema <= 3.54.2 - Missing Authorization to Authenticated (Subscriber+)โฆ
The WordLift โ AI powered SEO โ Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'wl_config_plugin' AJAX action in all versions up to, and including, 3.54.2. This makes it possible for unauthenticated attackers to update the plugin's settings.
6.5
CVE-2024-12332 - School Management System โ WPSchoolPress <= 2.2.14 - Authenticated (Student/Parent+) SQL Injection
The School Management System โ WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makesโฆ
4.3
CVE-2024-12140 - Elementor AI Addons โ 70 Widgets, Premium Templates, Ultimate Elements <= 2.2.1 - Authenticated (Coโฆ
The Elementor Addons AI Addons โ 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render function due to insufficient restrictions on which templates can be included. This makes it possiblโฆ
9.8
CVE-2024-12264 - PayU CommercePro Plugin <= 3.8.3 - Unauthenticated Privilege Escalation
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost REST API endpoints not properly verifying a user's identity prior to settinโฆ
5.3
CVE-2024-11290 - Member Access <= 1.1.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposuโฆ
The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-levโฆ