6.1

CVSS3.1

CVE-2024-9208 - Enable Accessibility <= 1.4.1 - Reflected Cross-Site Scripting

The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.1. This makes it possible for unauthenticated attackers to inject arbitrโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12327 - LazyLoad Background Images <= 1.0.7 - Missing Authorization to Authenticated (Subscriber+) Plugin Sโ€ฆ

The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pblzbg_save_settings() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level acceโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-11496 - Infility Global <= 2.9.8 - Authenticated (Subscriber+) Missing Authorization to Plugin Options Updaโ€ฆ

The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_ajax function in all versions up to, and including, 2.9.8. This makes it possible for authenticated attackers, with Subscriber-level access and above,โ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:19 p.m.

5.3

CVSS3.1

CVE-2024-12159 - Optimize Your Campaigns โ€“ Google Shopping โ€“ Google Ads โ€“ Google Adwords <= 3.1 - Information Exposuโ€ฆ

The Optimize Your Campaigns โ€“ Google Shopping โ€“ Google Ads โ€“ Google Adwords plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1 due to the print_php_information.php being publicly accessible. This makes it possible for unauthenticated attackers to exโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-12256 - Simple Video Management System <= 1.0.4 - Reflected Cross-Site Scripting

The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analytics_video' parameter in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers toโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-12176 - WordLift โ€“ AI powered SEO โ€“ Schema <= 3.54.2 - Missing Authorization to Authenticated (Subscriber+)โ€ฆ

The WordLift โ€“ AI powered SEO โ€“ Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'wl_config_plugin' AJAX action in all versions up to, and including, 3.54.2. This makes it possible for unauthenticated attackers to update the plugin's settings.

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-12332 - School Management System โ€“ WPSchoolPress <= 2.2.14 - Authenticated (Student/Parent+) SQL Injection

The School Management System โ€“ WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makesโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 7:19 p.m.

4.3

CVSS3.1

CVE-2024-12140 - Elementor AI Addons โ€“ 70 Widgets, Premium Templates, Ultimate Elements <= 2.2.1 - Authenticated (Coโ€ฆ

The Elementor Addons AI Addons โ€“ 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render function due to insufficient restrictions on which templates can be included. This makes it possiblโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.8

CVSS3.1

CVE-2024-12264 - PayU CommercePro Plugin <= 3.8.3 - Unauthenticated Privilege Escalation

The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token and /wp-json/payu/v1/get-shipping-cost REST API endpoints not properly verifying a user's identity prior to settinโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-11290 - Member Access <= 1.1.6 - Unauthenticated Content Restriction Bypass to Sensitive Information Exposuโ€ฆ

The Member Access plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.6 via the WordPress core search feature. This makes it possible for unauthenticated attackers to extract sensitive data from posts that have been restricted to higher-levโ€ฆ

๐Ÿ“… Published: Jan. 7, 2025, 4:22 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 345234
Page 6867 of 34,524
ยซ previous page ยป next page
Filters