Latest CVE Feed
-
7.1
HIGHCVE-2024-54301
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FormFacade FormFacade allows Reflected XSS.This issue affects FormFacade: from n/a through 1.3.6.... Read more
Affected Products : formfacade- Published: Dec. 13, 2024
- Modified: Jun. 05, 2025
-
4.3
MEDIUMCVE-2023-41802
Missing Authorization vulnerability in Team Heateor Super Socializer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Super Socializer: from n/a through 7.13.54.... Read more
Affected Products : super_socializer- Published: Dec. 13, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2023-41695
Missing Authorization vulnerability in Analytify Analytify allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Analytify: from n/a through 5.1.0.... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: Dec. 13, 2024
- Modified: Jun. 05, 2025
-
6.5
MEDIUMCVE-2022-46795
Missing Authorization vulnerability in Tyche Softwares Print Invoice & Delivery Notes for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Print Invoice & Delivery Notes for WooCommerce: from n/a throu... Read more
Affected Products : print_invoice_\&_delivery_notes_for_woocommerce- Published: Dec. 13, 2024
- Modified: Jun. 05, 2025
-
6.1
MEDIUMCVE-2024-11356
The tourmaster WordPress plugin before 5.3.4 does not sanitise and escape some parameters when outputting them in the page, which could allow unauthenticated users to perform Cross-Site Scripting attacks.... Read more
Affected Products : tour_master- Published: Jan. 06, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2022-45830
Missing Authorization vulnerability in Analytify.This issue affects Analytify: from n/a through 4.2.3.... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: Jan. 02, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-37235
Cross-Site Request Forgery (CSRF) vulnerability in Groundhogg Inc. Groundhogg allows Cross Site Request Forgery.This issue affects Groundhogg: from n/a through 3.4.2.3.... Read more
Affected Products : groundhogg- Published: Jan. 02, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.9
MEDIUMCVE-2024-11357
The goodlayers-core WordPress plugin before 2.0.10 does not sanitise and escape some of its settings, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.... Read more
Affected Products : goodlayers_core- Published: Jan. 02, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-56229
Cross-Site Request Forgery (CSRF) vulnerability in Searchiq SearchIQ.This issue affects SearchIQ: from n/a through 4.6.... Read more
Affected Products : searchiq- Published: Dec. 31, 2024
- Modified: Jun. 05, 2025
-
6.1
MEDIUMCVE-2024-56175
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in list item names.... Read more
Affected Products : configured_commerce- Published: Dec. 18, 2024
- Modified: Jun. 05, 2025
-
8.1
HIGHCVE-2024-56174
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in search history.... Read more
Affected Products : configured_commerce- Published: Dec. 18, 2024
- Modified: Jun. 05, 2025
-
4.7
MEDIUMCVE-2024-56173
In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from JavaScript in an SVG document.... Read more
Affected Products : configured_commerce- Published: Dec. 18, 2024
- Modified: Jun. 05, 2025
-
6.4
MEDIUMCVE-2024-1679
The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the template and javascript label fields in all versions up to, and including, 3.4.6 due ... Read more
Affected Products : print_labels_with_barcodes- Published: May. 02, 2024
- Modified: Jun. 05, 2025
-
8.8
HIGHCVE-2024-1677
The Print Labels with Barcodes. Create price tags, product labels, order labels for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data, modification of data, and loss of data due to an improper capability check on 42 separate AJ... Read more
Affected Products : print_labels_with_barcodes- Published: May. 02, 2024
- Modified: Jun. 05, 2025
-
5.3
MEDIUMCVE-2024-1584
The Analytify – Google Analytics Dashboard For WordPress (GA4 analytics made easy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wpa_check_authentication' function in all versions up to, ... Read more
Affected Products : analytify_-_google_analytics_dashboard- Published: May. 02, 2024
- Modified: Jun. 05, 2025
-
7.5
HIGHCVE-2024-1895
The Event Monster – Event Management, Tickets Booking, Upcoming Event plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.3.4 via deserialization via shortcode of untrusted input from a custom meta value. Thi... Read more
Affected Products : event_monster- Published: Apr. 30, 2024
- Modified: Jun. 05, 2025
-
5.3
MEDIUMCVE-2024-3678
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.4.2. This makes it possible for unauthenticated attackers to view limited information from pas... Read more
Affected Products : blog2social- Published: Apr. 26, 2024
- Modified: Jun. 05, 2025
-
6.4
MEDIUMCVE-2024-2477
The wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Alternative Text' field of an uploaded image in all versions up to, and including, 7.6.15 due to insufficient input sanitization and output escaping. This makes it pos... Read more
Affected Products : wpdiscuz- Published: Apr. 23, 2024
- Modified: Jun. 05, 2025
-
9.9
CRITICALCVE-2024-3549
The Blog2Social: Social Media Auto Post & Scheduler plugin for WordPress is vulnerable to SQL Injection via the 'b2sSortPostType' parameter in all versions up to, and including, 7.4.1 due to insufficient escaping on the user supplied parameter and lack of... Read more
Affected Products : blog2social- Published: Jun. 11, 2024
- Modified: Jun. 05, 2025
-
7.2
HIGHCVE-2024-5207
The POST SMTP – The #1 WordPress SMTP Plugin with Advanced Email Logging and Delivery Failure Notifications plugin for WordPress is vulnerable to time-based SQL Injection via the selected parameter in all versions up to, and including, 2.9.3 due to insuff... Read more
Affected Products : post_smtp- Published: May. 30, 2024
- Modified: Jun. 05, 2025