4.3

CVSS3.1

CVE-2024-10693 - SKT Addons for Elementor <= 3.3 - Authenticated (Contributor+) Post Disclosure

The SKT Addons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.3 via the Unfold widget due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contributor-level access …

📅 Published: Nov. 9, 2024, 3:30 a.m. 🔄 Last Modified: April 8, 2026, 5:05 p.m.

9.8

CVSS3.1

CVE-2024-10627 - WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Upload

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ajax_manage_file_chunk_upload() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to upload arbitrary…

📅 Published: Nov. 9, 2024, 3:30 a.m. 🔄 Last Modified: April 8, 2026, 4:38 p.m.

8.8

CVSS3.1

CVE-2024-10626 - WooCommerce Support Ticket System <= 17.7 - Authenticated (Subscriber+) Arbitrary File Deletion

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for authenticated attackers, with Subscriber-level a…

📅 Published: Nov. 9, 2024, 3:18 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

9.8

CVSS3.1

CVE-2024-10625 - WooCommerce Support Ticket System <= 17.7 - Unauthenticated Arbitrary File Deletion

The WooCommerce Support Ticket System plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete_tmp_uploaded_file() function in all versions up to, and including, 17.7. This makes it possible for unauthenticated attackers to delete arbitrar…

📅 Published: Nov. 9, 2024, 3:18 a.m. 🔄 Last Modified: April 8, 2026, 5:28 p.m.

8.8

CVSS3.1

CVE-2024-10674 - Th Shop Mania <= 1.4.9 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

The Th Shop Mania theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the th_shop_mania_install_and_activate_callback() function in all versions up to, and including, 1.4.9. This makes it possible for authenticated attackers, with Sub…

📅 Published: Nov. 9, 2024, 3:18 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.1

CVSS3.1

CVE-2024-9226 - Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.6 - Reflected Cross-Si…

The Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.7.6. This makes it possible for unauthentica…

📅 Published: Nov. 9, 2024, 3:18 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-10673 - Top Store <= 1.5.4 - Authenticated (Subscriber+) Arbitrary Plugin Installation/Activation

The Top Store theme for WordPress is vulnerable to unauthorized arbitrary plugin installation due to a missing capability check on the top_store_install_and_activate_callback() function in all versions up to, and including, 1.5.4. This makes it possible for authenticated attackers, with subscriber-…

📅 Published: Nov. 9, 2024, 3:17 a.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.

6.4

CVSS3.1

CVE-2024-8960 - Cowidgets – Elementor Addons <= 1.2.0 - Authenticated (Author+) Stored Cross-Site Scripting via SVG…

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level acces…

📅 Published: Nov. 9, 2024, 2:32 a.m. 🔄 Last Modified: April 8, 2026, 5:34 p.m.

5.3

CVSS3.1

CVE-2024-10779 - Cowidgets – Elementor Addons <= 1.2.0 - Authenticated (Contributor+) Post Disclosure

The Cowidgets – Elementor Addons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.0 via the 'ce_template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for authenticated attackers, with Contribut…

📅 Published: Nov. 9, 2024, 2:32 a.m. 🔄 Last Modified: April 8, 2026, 5:31 p.m.

6.5

CVSS3.1

CVE-2024-10294 - CE21 Suite <= 2.2.0 - Missing Authorization to Unauthenticated Plugin Settings Change

The CE21 Suite plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ce21_single_sign_on_save_api_settings' function in versions up to, and including, 2.2.0. This makes it possible for unauthenticated attackers to change plugin settings.

📅 Published: Nov. 9, 2024, 2:32 a.m. 🔄 Last Modified: April 8, 2026, 5:24 p.m.
Total resulsts: 345149
Page 7567 of 34,515
« previous page » next page
Filters