6.4

CVSS3.1

CVE-2024-12461 - WP-Revive Adserver <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The WP-Revive Adserver plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wprevive_async' shortcode in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authent…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 4:57 p.m.

6.4

CVSS3.1

CVE-2024-11433 - Surbma | SalesAutopilot Shortcode <= 2.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Surbma | SalesAutopilot Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sa-form' shortcode in all versions up to, and including, 2.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for a…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-11914 - Gutenberg Blocks and Page Layouts – Attire Blocks <= 1.9.5 - Authenticated (Contributor+) Stored Cr…

The Gutenberg Blocks and Page Layouts – Attire Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'attire-blocks/post-carousel' block in all versions up to, and including, 1.9.5 due to insufficient input sanitization and output escaping. This makes it possible for auth…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

6.4

CVSS3.1

CVE-2024-11427 - Catch Popup <= 1.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Catch Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'catch-popup' shortcode in all versions up to, and including, 1.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated att…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.

6.1

CVSS3.1

CVE-2024-11279 - Schema App Structured Data <= 2.2.4 - Reflected Cross-Site Scripting

The Schema App Structured Data plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.2.4. This makes it possible for unauthenticated attackers to inject arbitrary web scrip…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 6:19 p.m.

8.8

CVSS3.1

CVE-2024-11689 - HQ Rental Software <= 1.5.29 - Cross-Site Request Forgery to Arbitrary Options Update

The HQ Rental Software plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.29. This is due to missing or incorrect nonce validation on the displaySettingsPage() function. This makes it possible for unauthenticated attackers to update arbitrary …

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 4:44 p.m.

6.4

CVSS3.1

CVE-2024-11413 - HostFact bestelformulier integratie <= 1.1 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The HostFact bestelformulier integratie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bestelformulier' shortcode in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it poss…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

6.5

CVSS3.1

CVE-2024-11430 - SQL Chart Builder <= 2.3.6 - Authenticated (Contributor+) SQL Injection

The SQL Chart Builder plugin for WordPress is vulnerable to SQL Injection via the 'arg1' arg of the 'gvn_schart_2' shortcode in all versions up to, and including, 2.3.6 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This ma…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 4:41 p.m.

4.3

CVSS3.1

CVE-2024-12341 - Custom Skins Contact Form 7 <= 1.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary…

The Custom Skins Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'cf7cs_action_callback' function in all versions up to, and including, 1.0. This makes it possible for authenticated attackers, with Subscriber-level acce…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 4:40 p.m.

6.4

CVSS3.1

CVE-2024-11442 - Horizontal scroll image slideshow <= 10.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Horizontal scroll image slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'horizontal-scroll-image-slideshow' shortcode in all versions up to, and including, 10.1 due to insufficient input sanitization and output escaping on user supplied attributes. T…

📅 Published: Dec. 12, 2024, 3:23 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.
Total resulsts: 343436
Page 6935 of 34,344
« previous page » next page
Filters