Latest CVE Feed
-
5.9
MEDIUMCVE-2025-24644
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels allows Stored XSS. This issue affects WooCommerce PDF Invoices, Pac... Read more
Affected Products : woocommerce_pdf_invoices\,_packing_slips\,_delivery_notes_and_shipping_labels- Published: Jan. 24, 2025
- Modified: Feb. 11, 2025
-
6.5
MEDIUMCVE-2025-24638
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Pete Dring Create with Code allows DOM-Based XSS. This issue affects Create with Code: from n/a through 1.4.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
7.1
HIGHCVE-2025-24636
Cross-Site Request Forgery (CSRF) vulnerability in Laymance Technologies LLC MachForm Shortcode allows Stored XSS. This issue affects MachForm Shortcode: from n/a through 1.4.1.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.9
MEDIUMCVE-2025-24634
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Svetoslav Marinov (Slavi) Orbisius Simple Notice allows Stored XSS. This issue affects Orbisius Simple Notice: from n/a through 1.1.3.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.3
MEDIUMCVE-2025-24633
Missing Authorization vulnerability in silverplugins217 Build Private Store For Woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Build Private Store For Woocommerce: from n/a through 1.0.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Mar. 03, 2025
-
6.5
MEDIUMCVE-2025-24627
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Linnea Huxford, LinSoftware Blur Text allows Stored XSS. This issue affects Blur Text: from n/a through 1.0.0.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2025-24625
Missing Authorization vulnerability in Marco Almeida | Webdados Taxonomy/Term and Role based Discounts for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Taxonomy/Term and Role based Discounts for W... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2025-24623
Cross-Site Request Forgery (CSRF) vulnerability in Really Simple Security Really Simple SSL allows Cross Site Request Forgery. This issue affects Really Simple SSL: from n/a through 9.1.4.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.4
MEDIUMCVE-2025-24622
Cross-Site Request Forgery (CSRF) vulnerability in PickPlugins Job Board Manager allows Cross Site Request Forgery. This issue affects Job Board Manager: from n/a through 2.1.59.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
8.8
HIGHCVE-2025-24618
Missing Authorization vulnerability in ElementInvader ElementInvader Addons for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementInvader Addons for Elementor: from n/a through 1.3.1.... Read more
Affected Products : elementinvader_addons_for_elementor- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2025-24613
Missing Authorization vulnerability in Foliovision FV Thoughtful Comments allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FV Thoughtful Comments: from n/a through 0.3.5.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.9
MEDIUMCVE-2025-24611
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Smackcoders WP Ultimate Exporter allows Absolute Path Traversal. This issue affects WP Ultimate Exporter: from n/a through 2.9.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2025-24610
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Christian Leuenberg, L.net Web Solutions Restrict Anonymous Access allows Stored XSS. This issue affects Restrict Anonymous Access: from n/a through 1.2.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
5.4
MEDIUMCVE-2025-24604
Missing Authorization vulnerability in Vikas Ratudi VForm allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects VForm: from n/a through 3.0.5.... Read more
Affected Products : lifetime_free_drag_\&_drop_contact_form_builder- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
9.8
CRITICALCVE-2025-24596
Missing Authorization vulnerability in WC Product Table WooCommerce Product Table Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WooCommerce Product Table Lite: from n/a through 3.8.7.... Read more
- Published: Jan. 24, 2025
- Modified: Feb. 11, 2025
-
6.5
MEDIUMCVE-2025-24595
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins All Embed – Elementor Addons allows Stored XSS. This issue affects All Embed – Elementor Addons: from n/a through 1.1.3.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2025-24594
Missing Authorization vulnerability in Speedcomp Linet ERP-Woocommerce Integration allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Linet ERP-Woocommerce Integration: from n/a through 3.5.7.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
8.8
HIGHCVE-2025-24591
Missing Authorization vulnerability in NinjaTeam GDPR CCPA Compliance Support allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GDPR CCPA Compliance Support: from n/a through 2.7.1.... Read more
- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
4.3
MEDIUMCVE-2025-24589
Missing Authorization vulnerability in JS Morisset JSM Show Post Metadata allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JSM Show Post Metadata: from n/a through 4.6.0.... Read more
Affected Products :- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025
-
6.5
MEDIUMCVE-2025-24588
Missing Authorization vulnerability in Patreon Patreon WordPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Patreon WordPress: from n/a through 1.9.1.... Read more
Affected Products : patreon_wordpress- Published: Jan. 24, 2025
- Modified: Jan. 24, 2025