Latest CVE Feed
-
6.1
MEDIUMCVE-2024-9377
The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.... Read more
Affected Products : products\,_order_\&_customers_export_for_woocommerce- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-9205
The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 4.2.8. This makes it possible ... Read more
Affected Products : maximum_products_per_user_for_woocommerce- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9072
The GDPR-Extensions-com – Consent Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible... Read more
Affected Products : consent_manager- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9066
The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.10 due to insufficient input sanitization and output escaping. This makes it possible for authen... Read more
Affected Products : marketing_and_seo_booster- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
5.3
MEDIUMCVE-2024-9065
The WP Helper Premium plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'whp_smtp_send_mail_test' function in all versions up to, and including, 4.6.1. This makes it possible for unauthenticat... Read more
Affected Products : wp_helper_premium- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9064
The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticate... Read more
Affected Products : elementor_inline_svg- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9057
The Curator.io: Show all your social media posts in a beautiful feed. plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘feed_id’ attribute in all versions up to, and including, 1.9 due to insufficient input sanitization and output... Read more
Affected Products : curator.io- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-8987
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's youzify_media shortcode in all versions up to, and including, 1.3.0 due t... Read more
Affected Products : youzify- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-8729
The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.4.5. This makes it possible for unauthentica... Read more
Affected Products : easy_social_share_buttons- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
5.3
MEDIUMCVE-2024-8513
The QA Analytics – Web Analytics Tool with Heatmaps & Session Replay Across All Pages plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_save_plugin_config() function in all versions up to... Read more
Affected Products : qa_analytics- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
4.3
MEDIUMCVE-2024-8477
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. This is due to missing or incorrect nonce validation on ... Read more
Affected Products : newsletter\,_smtp\,_email_marketing_and_subscribe- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
7.5
HIGHCVE-2024-6747
Information leakage in mknotifyd in Checkmk before 2.3.0p18, 2.2.0p36, 2.1.0p49 and in 2.0.0p39 (EOL) allows attacker to get potentially sensitive data... Read more
- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
7.8
HIGHCVE-2024-33578
A DLL hijack vulnerability was reported in Lenovo Leyun that could allow a local attacker to execute code with elevated privileges.... Read more
Affected Products : leyun- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
6.9
MEDIUMCVE-2024-4658
SQL Injection: Hibernate vulnerability in TE Informatics Nova CMS allows SQL Injection.This issue affects Nova CMS: before 5.0.... Read more
Affected Products :- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
9.2
CRITICALCVE-2023-25581
pac4j is a security framework for Java. `pac4j-core` prior to version 4.0.0 is affected by a Java deserialization vulnerability. The vulnerability affects systems that store externally controlled values in attributes of the `UserProfile` class from pac4j-... Read more
Affected Products : pac4j- Published: Oct. 10, 2024
- Modified: Oct. 15, 2024
-
8.8
HIGHCVE-2024-48827
An issue in sbondCo Watcharr v.1.43.0 allows a remote attacker to execute arbitrary code and escalate privileges via the Change Password function.... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-9610
The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.7.13. This makes it possible for unauthenticated att... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-9346
The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. This makes it possible fo... Read more
Affected Products :- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
6.5
MEDIUMCVE-2024-7514
The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7. This makes it possible for authentica... Read more
Affected Products : wordpress_comments_import_and_export- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-9221
The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 0.21.10. This makes it possible for unauthenticated attackers t... Read more
Affected Products : tainacan- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024