7.3

CVSS3.1

CVE-2024-10263 - Tickera – WordPress Event Ticketing <= 3.5.4.4 - Unauthenticated Arbitrary Shortcode Execution

The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.5.4.4. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes …

πŸ“… Published: Nov. 5, 2024, 12:45 p.m. πŸ”„ Last Modified: April 8, 2026, 4:59 p.m.

5.4

CVSS3.1

CVE-2024-9867 - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arr…

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Open Map Widget' marker_content parameter in all versions up to, and including, 5.10.2 due to insufficient input san…

πŸ“… Published: Nov. 5, 2024, 11:32 a.m. πŸ”„ Last Modified: April 8, 2026, 5:23 p.m.

6.5

CVSS3.1

CVE-2024-9657 - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arr…

The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the β€˜tooltip' parameter in all versions up to, and including, 5.10.2 due to insufficient input sanitization and output es…

πŸ“… Published: Nov. 5, 2024, 11:32 a.m. πŸ”„ Last Modified: April 8, 2026, 4:58 p.m.

6.6

CVSS3.1

CVE-2024-51530 -

LaunchAnywhere vulnerability in the account module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

πŸ“… Published: Nov. 5, 2024, 11:19 a.m. πŸ”„ Last Modified: Nov. 7, 2024, 7:56 p.m.

5.5

CVSS3.1

CVE-2024-51529 -

Data verification vulnerability in the battery module Impact: Successful exploitation of this vulnerability may affect function stability.

πŸ“… Published: Nov. 5, 2024, 11:18 a.m. πŸ”„ Last Modified: Nov. 7, 2024, 7:56 p.m.

6.4

CVSS3.1

CVE-2024-9178 - XT Floating Cart for WooCommerce <= 2.8.2 - Authenticated (Author+) Stored Cross-Site Scripting via…

The XT Floating Cart for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.8.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level a…

πŸ“… Published: Nov. 5, 2024, 11 a.m. πŸ”„ Last Modified: April 8, 2026, 5:09 p.m.

4.3

CVSS3.1

CVE-2024-10319 - 140+ Widgets | Xpro Addons For Elementor – FREE <= 1.4.6 - Authenticated (Contributor+) Sensitive I…

The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6 via the render function in widgets/content-toggle/layout/frontend.php. This makes it possible for authenticated attackers, with Contri…

πŸ“… Published: Nov. 5, 2024, 11 a.m. πŸ”„ Last Modified: April 8, 2026, 4:46 p.m.

4

CVSS3.1

CVE-2024-51528 -

Vulnerability of improper log printing in the Super Home Screen module Impact: Successful exploitation of this vulnerability may affect service confidentiality.

πŸ“… Published: Nov. 5, 2024, 9:33 a.m. πŸ”„ Last Modified: Nov. 7, 2024, 7:57 p.m.

9.8

CVSS3.1

CVE-2024-10687 - Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell …

The Photos, Files, YouTube, Twitter, Instagram, TikTok, Ecommerce Contest Gallery – Upload, Vote, Sell via PayPal, Social Share Buttons plugin for WordPress is vulnerable to time-based SQL Injection via the $collectedIds parameter in all versions up to, and including, 24.0.3 due to insufficient esc…

πŸ“… Published: Nov. 5, 2024, 9:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:34 p.m.

4.4

CVSS3.1

CVE-2024-9878 - Photo Gallery by 10Web <= 1.8.30 - Authenticated (Administrator+) Stored Cross-Site Scripting

The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.8.30 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers…

πŸ“… Published: Nov. 5, 2024, 9:30 a.m. πŸ”„ Last Modified: April 8, 2026, 5:19 p.m.
Total resulsts: 346580
Page 7755 of 34,658
Β« previous page Β» next page
Filters