Latest CVE Feed
-
6.4
MEDIUMCVE-2024-12515
The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, 1.8.8 due to insufficient input sanitization and output escaping. This makes it possibl... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-12514
The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' shortcode in all versions up to, and including, 2.2.2 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-12496
The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissions' shortcode in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping on user supplied... Read more
Affected Products : linear- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-12493
The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' shortcode in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping on user supplied attribu... Read more
Affected Products : files_download_delay- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-12491
The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and including, 2.11.2 due to insufficient input sanitization and output escaping on user su... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12394
The Action Network plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to in... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
7.5
HIGHCVE-2024-12330
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via publicly accessible back-up files. This makes it possible for un... Read more
Affected Products : wp_database_backup- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2024-12285
The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versions up to, and including, 5.27 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated a... Read more
Affected Products : sema_api- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.3
MEDIUMCVE-2024-12249
The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings() function in all versions up to, and including, 1.4.5. This makes it possible for authenticated attack... Read more
Affected Products : gs_insever_portfolio- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Authorization
-
6.1
MEDIUMCVE-2024-12222
The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvsfw_bulk_label_url’ parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping. Th... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12218
The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect nonce validation. This makes it possible for unauthenticat... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.3
MEDIUMCVE-2024-12206
The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing or incorrect nonce validation on the stm_header_builder page. This makes it po... Read more
Affected Products : pearl_header_builder- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2024-12122
The ResAds plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via multiple parameters in all versions up to, and including, 2.0.6 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated atta... Read more
Affected Products : resads- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-12067
The WP Travel – Ultimate Travel Booking System, Tour Management Engine plugin for WordPress is vulnerable to SQL Injection via the 'booking_itinerary' parameter of the 'wptravel_get_booking_data' function in all versions up to, and including, 10.0.0 due t... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Injection
-
6.4
MEDIUMCVE-2024-11929
The Responsive FlipBook Plugin Wordpress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the rfbwp_save_settings() functionin all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This m... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2024-11907
The Skyword API Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skyword_iframe' shortcode in all versions up to, and including, 2.5.2 due to insufficient input sanitization and output escaping on user supplied at... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-11815
The Pósturinn\'s Shipping with WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the printed_marked and nonprinted_marked parameters in all versions up to, and including, 1.3.1 due to insufficient input sanitization... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
-
6.1
MEDIUMCVE-2024-11686
The WhatsApp 🚀 click to chat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'manycontacts_code' parameter in all versions up to, and including, 3.0.4 due to insufficient input sanitization and output escaping. This makes it p... Read more
Affected Products :- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-11642
The Post Grid Master – Custom Post Types, Taxonomies & Ajax Filter Everything with Infinite Scroll, Load More, Pagination & Shortcode Builder plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.4.12 via the '... Read more
Affected Products : post_grid_master- Published: Jan. 09, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Path Traversal
-
6.1
MEDIUMCVE-2024-11328
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.13.2. This makes it... Read more
Affected Products : learning_management_system- Published: Jan. 09, 2025
- Modified: Jan. 09, 2025
- Vuln Type: Cross-Site Scripting