5.4

CVSS3.1

CVE-2024-9630 - WPS Telegram Chat <= 4.6.0 - Missing Authorization to Information Exposure

The WPS Telegram Chat plugin for WordPress is vulnerable to authorization bypass due to a missing capability check when accessing messages in versions up to, and including, 4.6.0. This makes it possible for unauthenticated attackers to view the messages that are sent through the Telegram Bot API.

πŸ“… Published: Oct. 25, 2024, 7:38 a.m. πŸ”„ Last Modified: April 8, 2026, 6:22 p.m.

8.8

CVSS3.1

CVE-2024-9598 - AMP for WP – Accelerated Mobile Pages <= 1.0.99.1 - Cross-Site Request Forgery to Privilege Escalat…

The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.99.1. This is due to missing or incorrect nonce validation on the 'proxy' function. This makes it possible for unauthenticated attackers to send the l…

πŸ“… Published: Oct. 25, 2024, 7:37 a.m. πŸ”„ Last Modified: April 8, 2026, 4:58 p.m.

6.4

CVSS3.1

CVE-2024-10150 - Bamazoo – Button Generator <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via dg…

The Bamazoo – Button Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's dgs shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated …

πŸ“… Published: Oct. 25, 2024, 7:37 a.m. πŸ”„ Last Modified: April 8, 2026, 4:53 p.m.

6.4

CVSS3.1

CVE-2024-10342 - League of Legends Shortcodes <= 1.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting vi…

The League of Legends Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcodes in versions up to, and including, 1.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with c…

πŸ“… Published: Oct. 25, 2024, 7:37 a.m. πŸ”„ Last Modified: April 8, 2026, 4:49 p.m.

6.5

CVSS3.1

CVE-2024-10341 - League of Legends Shortcodes <= 1.0.1 - Authenticated (Contributor+) SQL Injection via Shortcode

The League of Legends Shortcodes plugin for WordPress is vulnerable to SQL Injection via the plugin's shortcode in versions up to, and including, 1.0.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible fo…

πŸ“… Published: Oct. 25, 2024, 7:37 a.m. πŸ”„ Last Modified: April 8, 2026, 4:41 p.m.

6.3

CVSS3.1

CVE-2024-50583 -

Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings.

πŸ“… Published: Oct. 25, 2024, 7:04 a.m. πŸ”„ Last Modified: July 13, 2025, 11:06 a.m.

6.1

CVSS3.1

CVE-2024-9607 - 10Web Social Post Feed <= 1.2.9 - Reflected Cross-Site Scripting

The 10Web Social Post Feed plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts i…

πŸ“… Published: Oct. 25, 2024, 6:51 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.

8.8

CVSS3.1

CVE-2024-9235 - Mapster WP Maps <= 1.5.0 - Incorrect Authorization to Authenticated (Contributor+) Arbitrary Option…

The Mapster WP Maps plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to an insufficient capability check on the mapster_wp_maps_set_option_from_js() function in all versions up to, and including, 1.5.0. This makes it possible for auth…

πŸ“… Published: Oct. 25, 2024, 6:51 a.m. πŸ”„ Last Modified: April 8, 2026, 5:17 p.m.

6.4

CVSS3.1

CVE-2024-10148 - Awesome buttons <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via btn2 Shortcode

The Awesome buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn2 shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…

πŸ“… Published: Oct. 25, 2024, 6:51 a.m. πŸ”„ Last Modified: April 8, 2026, 5:04 p.m.

8.1

CVSS3.1

CVE-2024-10011 - BuddyPress <= 14.1.0 - Authenticated (Subscriber+) Directory Traversal

The BuddyPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 14.1.0 via the id parameter. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of the originally intended dire…

πŸ“… Published: Oct. 25, 2024, 6:51 a.m. πŸ”„ Last Modified: April 8, 2026, 6:19 p.m.
Total resulsts: 343921
Page 7618 of 34,393
Β« previous page Β» next page
Filters