Latest CVE Feed
-
4.3
MEDIUMCVE-2024-10533
The WP Chat App plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the ajax_install_plugin() function in all versions up to, and including, 3.6.8. This makes it possible for authenticated attackers,... Read more
Affected Products : wp_chat_app- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-10147
The Steel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's btn shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it po... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-10592
The Mapster WP Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the popup class parameter in all versions up to, and including, 1.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
5.3
MEDIUMCVE-2024-11094
The 404 Solution plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.35.17 via the export feature. This makes it possible for unauthenticated attackers to extract sensitive data such as redirects in... Read more
Affected Products : 404_solution- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
7.2
HIGHCVE-2024-9887
The Login using WordPress Users ( WP as SAML IDP ) plugin for WordPress is vulnerable to time-based SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.15.6 due to insufficient escaping on the user supplied parameter and lack of s... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.9
CRITICALCVE-2024-52399
Unrestricted Upload of File with Dangerous Type vulnerability in Clarisse K. Writer Helper allows Upload a Web Shell to a Web Server.This issue affects Writer Helper: from n/a through 3.1.6.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.9
CRITICALCVE-2024-52403
Unrestricted Upload of File with Dangerous Type vulnerability in WPExperts User Management allows Upload a Web Shell to a Web Server.This issue affects User Management: from n/a through 1.1.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.9
CRITICALCVE-2024-52405
Unrestricted Upload of File with Dangerous Type vulnerability in Bikram Joshi B-Banner Slider allows Upload a Web Shell to a Web Server.This issue affects B-Banner Slider: from n/a through 1.1.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.9
CRITICALCVE-2024-52407
Unrestricted Upload of File with Dangerous Type vulnerability in codeSavory BasePress Migration Tools allows Upload a Web Shell to a Web Server.This issue affects BasePress Migration Tools: from n/a through 1.0.0.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-10015
The ConvertCalculator for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' and 'type' parameters in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it ... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-52409
Deserialization of Untrusted Data vulnerability in Phan An AJAX Random Posts allows Object Injection.This issue affects AJAX Random Posts: from n/a through 0.3.3.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
4.3
MEDIUMCVE-2024-10795
The Popularis Extra plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.7 via the 'elementor-template' shortcode due to insufficient restrictions on which posts can be included. This makes it possible for a... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-52412
Deserialization of Untrusted Data vulnerability in Stephen Cui Xin allows Object Injection.This issue affects Xin: from n/a through 1.0.8.1.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
8.8
HIGHCVE-2024-52415
Cross-Site Request Forgery (CSRF) vulnerability in Skpstorm SK WP Settings Backup allows Object Injection.This issue affects SK WP Settings Backup: from n/a through 1.0.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
7.5
HIGHCVE-2024-9935
The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the c... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.4
MEDIUMCVE-2024-9386
The Exclusive Divi – Divi Preloader, Modules for Divi & Extra Theme plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
5.4
MEDIUMCVE-2024-11085
The WP Log Viewer plugin for WordPress is vulnerable to unauthorized use of functionality due to a missing capability check on several AJAX actions in all versions up to, and including, 1.2.1. This makes it possible for authenticated attackers, with Subsc... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
6.1
MEDIUMCVE-2021-1444
A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to conduct cross-site scripting (XSS) attacks aga... Read more
Affected Products : adaptive_security_appliance_software- Published: Nov. 18, 2024
- Modified: Nov. 18, 2024
-
9.8
CRITICALCVE-2024-52411
Deserialization of Untrusted Data vulnerability in Flowcraft UX Design Studio Advanced Personalization allows Object Injection.This issue affects Advanced Personalization: from n/a through 1.1.2.... Read more
Affected Products :- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024
-
5.3
MEDIUMCVE-2024-10861
The Popup Box – Create Countdown, Coupon, Video, Contact Form Popups plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the deactivate_plugin_option() function in all versions up to, and including,... Read more
Affected Products : popup_box- Published: Nov. 16, 2024
- Modified: Nov. 18, 2024