0.0

CVE-2024-12208 -

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2024-43269. Reason: This candidate is a reservation duplicate of CVE-2024-43269. Notes: All CVE users should reference CVE-2024-43269 instead of this candidate. All references and descriptions in this candidate have been removed to prev…

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: Jan. 17, 2025, 5:15 p.m.

9.8

CVSS3.1

CVE-2024-12470 - School Management System – SakolaWP <= 1.0.8 - Unauthenticated Privilege Escalation

The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly limiting what roles a user can register as. This makes it possible for unauthenticated attackers to r…

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9208 - Enable Accessibility <= 1.4.1 - Reflected Cross-Site Scripting

The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.1. This makes it possible for unauthenticated attackers to inject arbitr…

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-12327 - LazyLoad Background Images <= 1.0.7 - Missing Authorization to Authenticated (Subscriber+) Plugin S…

The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pblzbg_save_settings() function in all versions up to, and including, 1.0.7. This makes it possible for authenticated attackers, with Subscriber-level acce…

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-11496 - Infility Global <= 2.9.8 - Authenticated (Subscriber+) Missing Authorization to Plugin Options Upda…

The Infility Global plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the infility_global_ajax function in all versions up to, and including, 2.9.8. This makes it possible for authenticated attackers, with Subscriber-level access and above,…

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: April 8, 2026, 7:19 p.m.

5.3

CVSS3.1

CVE-2024-12159 - Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords <= 3.1 - Information Exposu…

The Optimize Your Campaigns – Google Shopping – Google Ads – Google Adwords plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.1 due to the print_php_information.php being publicly accessible. This makes it possible for unauthenticated attackers to ex…

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-12256 - Simple Video Management System <= 1.0.4 - Reflected Cross-Site Scripting

The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analytics_video' parameter in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to…

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-12176 - WordLift – AI powered SEO – Schema <= 3.54.2 - Missing Authorization to Authenticated (Subscriber+)…

The WordLift – AI powered SEO – Schema plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'wl_config_plugin' AJAX action in all versions up to, and including, 3.54.2. This makes it possible for unauthenticated attackers to update the plugin's settings.

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2024-12332 - School Management System – WPSchoolPress <= 2.2.14 - Authenticated (Student/Parent+) SQL Injection

The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: April 8, 2026, 7:19 p.m.

4.3

CVSS3.1

CVE-2024-12140 - Elementor AI Addons – 70 Widgets, Premium Templates, Ultimate Elements <= 2.2.1 - Authenticated (Co…

The Elementor Addons AI Addons – 70 Widgets, Premium Templates, Ultimate Elements plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.1 via the render function due to insufficient restrictions on which templates can be included. This makes it possibl…

πŸ“… Published: Jan. 7, 2025, 4:22 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346536
Page 6997 of 34,654
Β« previous page Β» next page
Filters