6.4

CVSS3.1

CVE-2024-11786 - Login with Vipps and MobilePay <= 1.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'continue-with-vipps' shortcode in all versions up to, and including, 1.3.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 5:24 p.m.

6.1

CVSS3.1

CVE-2024-11458 - FAQ Builder AYS <= 1.7.1 - Reflected Cross-Site Scripting

The FAQ Builder AYS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'ays_faq_tab' parameter in all versions up to, and including, 1.7.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary w…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 5:20 p.m.

6.1

CVSS3.1

CVE-2024-11685 - Kudos Donations – Easy donations and payments with Mollie <= 3.2.9 - Reflected Cross-Site Scripting…

The `Kudos Donations – Easy donations and payments with Mollie` plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of `add_query_arg` without appropriate escaping on the URL in all versions up to, and including, 3.2.9. This makes it possible for unauthenticated atta…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 5:15 p.m.

6.1

CVSS3.1

CVE-2024-11366 - SEO Landing Page Generator <= 1.66.2 - Reflected Cross-Site Scripting

The SEO Landing Page Generator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.66.2. This makes it possible for unauthenticated attackers to inject arbitrary web scri…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 5:10 p.m.

6.4

CVSS3.1

CVE-2024-11333 - HLS Player <= 1.0.10 - Authenticated (Contributor+) Stored Cross-Site Scripting

The HLS Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hls_player' shortcode in all versions up to, and including, 1.0.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated atta…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 5:03 p.m.

7.2

CVSS3.1

CVE-2024-9669 - File Manager Pro – Filester <= 1.8.5 - Authenticated (Administrator+) Local JavaScript File Inclusi…

The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbi…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 5:02 p.m.

6.4

CVSS3.1

CVE-2024-11431 - Ragic Shortcode <= 1.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

The Ragic Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ragic' shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attacke…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 4:50 p.m.

7.5

CVSS3.1

CVE-2024-8066 - File Manager Pro – Filester <= 1.8.6- Authenticated (Subscriber+) Arbitrary File Upload

The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted p…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 4:42 p.m.

6.4

CVSS3.1

CVE-2024-11203 - EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audi…

The EmbedPress – Embed PDF, 3D Flipbook, Social Feeds, Google Docs, Vimeo, Wistia, YouTube Videos, Audios, Google Maps in Gutenberg Block & Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘provider_name parameter in all versions up to, and including, 4.1.3 due to…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 4:37 p.m.

6.4

CVSS3.1

CVE-2024-11788 - StreamWeasels YouTube Integration <= 1.3.6 - Authenticated (Contributor+) Stored Cross-Site Scripti…

The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and including, 1.3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it pos…

📅 Published: Nov. 28, 2024, 8:47 a.m. 🔄 Last Modified: April 8, 2026, 4:33 p.m.
Total resulsts: 343947
Page 7157 of 34,395
« previous page » next page
Filters