0.0
CVE-2024-10212 -
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
6.5
CVE-2024-49273 - WordPress ProfileGrid plugin <= 5.9.3 - Cross Site Request Forgery (CSRF) vulnerability
Missing Authorization vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities.This issue affects ProfileGrid : from n/a through <= 5.9.3.
5.4
CVE-2024-49293 - WordPress WP VR plugin <= 8.5.4 - Broken Access Control vulnerability
Missing Authorization vulnerability in RexTheme WP VR wpvr allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP VR: from n/a through <= 8.5.4.
4.3
CVE-2024-49321 - WordPress Simple Custom Post Order plugin <= 2.5.7 - Broken Access Control vulnerability
Missing Authorization vulnerability in colorlibplugins Simple Custom Post Order simple-custom-post-order allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple Custom Post Order: from n/a through <= 2.5.7.
6.5
CVE-2024-43945 - WordPress LatePoint plugin <= 4.9.91 - Cross Site Request Forgery (CSRF) vulnerability
Cross-Site Request Forgery (CSRF) vulnerability in Latepoint LatePoint allows Cross Site Request Forgery.This issue affects LatePoint: from n/a through 4.9.91.
7.2
CVE-2024-47328 - WordPress Recover WooCommerce Cart Abandonment, Newsletter, Email Marketing, Marketing Automation Bโฆ
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Aman FunnelKit Automations wp-marketing-automations allows SQL Injection.This issue affects FunnelKit Automations: from n/a through <= 3.1.2.
7.2
CVE-2024-8625 - TS Poll โ Survey, Versus Poll, Image Poll, Video Poll < 2.4.0 - Admin+ SQL Injection
The TS Poll WordPress plugin before 2.4.0 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
8.8
CVE-2024-10202 - Wellchoose Administrative Management System - OS Command Injection
Administrative Management System from Wellchoose has an OS Command Injection vulnerability, allowing remote attackers with regular privileges to inject and execute arbitrary OS commands.
8.8
CVE-2024-10201 - Wellchoose Administrative Management System - Arbitrary File Upload
Administrative Management System from Wellchoose does not properly validate uploaded file types, allowing remote attackers with regular privileges to upload and execute webshells.
7.5
CVE-2024-10200 - Wellchoose Administrative Management System - Arbitrary File Read through Path Traversal
Administrative Management System from Wellchoose has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to download arbitrary files on the server.