5.4

CVSS3.1

CVE-2024-10482 - Media Library Tools < 1.5.0 - Author+ Stored XSS via SVG

The Media File Rename, Find Unused File, Add Alt text, Caption, Desc For Image SEO WordPress plugin before 1.5.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.

๐Ÿ“… Published: Nov. 21, 2024, 6 a.m. ๐Ÿ”„ Last Modified: May 15, 2025, 4:23 p.m.

8.5

CVSS4.0

CVE-2024-7517 - Privileged escalation via crafted use of portcfg command

A command injection vulnerability in Brocade Fabric OS before 9.2.0c, and 9.2.1 through 9.2.1a on IP extension platforms could allow a local authenticated attacker to perform a privileged escalation via crafted use of the portcfg command. This specific exploitation is only possible on IP Extensionโ€ฆ

๐Ÿ“… Published: Nov. 21, 2024, 5:53 a.m. ๐Ÿ”„ Last Modified: Feb. 20, 2026, 9:22 p.m.

5.9

CVSS4.0

CVE-2024-10403 - SFTP/FTP password could be captured in plain text in Supportsave generated from SANnav

Brocade Fabric OS versions before 8.2.3e2, versions 9.0.0 through 9.2.0c, and 9.2.1 through 9.2.1a can capture the SFTP/FTP server password used for a firmware download operation initiated by SANnav or through WebEM in a weblinker core dump that is later captured via supportsave.

๐Ÿ“… Published: Nov. 21, 2024, 5:44 a.m. ๐Ÿ”„ Last Modified: Feb. 4, 2025, 3:28 p.m.

4.3

CVSS3.1

CVE-2024-10671 - Button Block โ€“ Get fully customizable & multi-functional buttons <= 1.1.4 - Authenticated (Contribuโ€ฆ

The Button Block โ€“ Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.4 via the [btn_block] shortcode due to insufficient restrictions on which posts can be included. This makes it possible for autheโ€ฆ

๐Ÿ“… Published: Nov. 21, 2024, 5:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:10 p.m.

4.3

CVSS3.1

CVE-2024-11334 - My Contador lesr <= 2.0 - Missing Authorization to Unauthenticated User Registration CSV Export

The My Contador lesr plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the exportar_registros() function in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to export user data.

๐Ÿ“… Published: Nov. 21, 2024, 5:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:04 p.m.

7.2

CVSS3.1

CVE-2024-10788 - Activity Log โ€“ Monitor & Record User Changes <= 2.11.1 - Unauthenticated Stored Cross-Site Scriptinโ€ฆ

The Activity Log โ€“ Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions up to, and including, 2.11.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers tโ€ฆ

๐Ÿ“… Published: Nov. 21, 2024, 5:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 5:01 p.m.

4.3

CVSS3.1

CVE-2024-10782 - Theme Builder For Elementor <= 1.2.2 - Authenticated (Contributor+) Post Disclosure

The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Conโ€ฆ

๐Ÿ“… Published: Nov. 21, 2024, 5:33 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-11438 - StreamWeasels Online Status Bar <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-status-bar' shortcode in all versions up to, and including, 2.1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possibleโ€ฆ

๐Ÿ“… Published: Nov. 21, 2024, 5:33 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.3

CVSS3.1

CVE-2024-10528 - Ultimate Member <= 2.8.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Profโ€ฆ

The Ultimate Member โ€“ User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to a missing capability check on the wp_ajax_um_resize_image() and ajax_resize_image() functions in all vโ€ฆ

๐Ÿ“… Published: Nov. 21, 2024, 5:33 a.m. ๐Ÿ”„ Last Modified: April 8, 2026, 4:34 p.m.

6.1

CVSS3.1

CVE-2024-9371 - Branda โ€“ White Label & Branding, Custom Login Page Customizer <= 3.4.19 - Reflected Cross-Site Scriโ€ฆ

The Branda โ€“ White Label & Branding, Custom Login Page Customizer plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.19. This makes it possible for unauthenticated โ€ฆ

๐Ÿ“… Published: Nov. 21, 2024, 4:24 a.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346120
Page 7459 of 34,612
ยซ previous page ยป next page
Filters