4.8
CVE-2024-8378 - Safe SVG < 2.2.6 - Author+ SVG Sanitisation Bypass
The Safe SVG WordPress plugin before 2.2.6 has its sanitisation code is only running for paths that call wp_handle_upload, but not for example for code that uses wp_handle_sideload which is often used to upload attachments via raw POST data.
4.3
CVE-2024-9926 - Jetpack < 13.9.1 - Subscriber+ Arbitrary Feedback Access
The Jetpack WordPress plugin does not have proper authorisation in one of its REST endpoint, allowing any authenticated users, such as subscriber to read arbitrary feedbacks data sent via the Jetpack Contact Form
7.5
CVE-2024-43438 - Moodle: idor in feedback non-respondents report allows messaging arbitrary site users
A flaw was found in Feedback. Bulk messaging in the activity's non-respondents report did not verify message recipients belonging to the set of users returned by the report.
7.2
CVE-2024-43436 - Moodle: site administration sql injection via xmldb editor
A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators.
8.1
CVE-2024-43434 - Moodle: csrf risk in feedback non-respondents report
The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
7.5
CVE-2024-43431 - Moodle: idor in badges allows deletion of arbitrary badges
A vulnerability was found in Moodle. Insufficient capability checks made it possible to delete badges that a user does not have permission to access.
7.7
CVE-2024-43428 - Moodle: cache poisoning via injection into storage
To address a cache poisoning risk in Moodle, additional validation for local storage was required.
7.5
CVE-2024-43426 - Moodle: arbitrary file read risk through pdftex
A flaw was found in pdfTeX. Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available, such as those with TeX Live installed.
8.1
CVE-2024-43425 - Moodle: remote code execution via calculated question types
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
6.4
CVE-2024-8442 - Prime Slider - Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider <= 3.15.โฆ
The Prime Slider โ Addons For Elementor (Revolution of a slider, Hero Slider, Ecommerce Slider) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Blog widget in all versions up to, and including, 3.15.18 due to insufficient input sanitization and output escaping on โฆ