Latest CVE Feed
-
5.9
MEDIUMCVE-2024-56288
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs allows Stored XSS.This issue affects WP Docs: from n/a through 2.2.1.... Read more
Affected Products : wp_docs- Published: Jan. 07, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-56287
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biztechc WP jQuery DataTable allows Stored XSS.This issue affects WP jQuery DataTable: from n/a through 4.0.1.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-56286
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Classic Addons Classic Addons – WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Classic Addons – WPBakery Page Builder: from n/a throu... Read more
Affected Products : page_builder- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2024-56285
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBits WPBITS Addons For Elementor Page Builder allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through 1.5.1.... Read more
Affected Products : wpbits_addons_for_elementor_page_builder- Published: Jan. 07, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2024-56284
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SSL Wireless SSL Wireless SMS Notification allows SQL Injection.This issue affects SSL Wireless SMS Notification: from n/a through 3.5.0.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2024-56283
Deserialization of Untrusted Data vulnerability in plainware.com Locatoraid Store Locator allows Object Injection.This issue affects Locatoraid Store Locator: from n/a through 3.9.50.... Read more
Affected Products : locatoraid- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-56282
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elicus WPMozo Addons Lite for Elementor allows PHP Local File Inclusion.This issue affects WPMozo Addons Lite for Elementor: from n/a ... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-56281
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodeMShop 워드프레스 결제 심플페이 allows PHP Local File Inclusion.This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.0.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-56280
Incorrect Privilege Assignment vulnerability in Amento Tech Pvt ltd WPGuppy allows Privilege Escalation.This issue affects WPGuppy: from n/a through 1.1.0.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2024-56279
Server-Side Request Forgery (SSRF) vulnerability in Tips and Tricks HQ Compact WP Audio Player allows Server Side Request Forgery.This issue affects Compact WP Audio Player: from n/a through 1.9.14.... Read more
Affected Products : compact_wp_audio_player- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
9.1
CRITICALCVE-2024-56278
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP Ultimate Exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through 2.9.1.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-56276
Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through 1.9.2.2.... Read more
- Published: Jan. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
4.1
MEDIUMCVE-2024-56275
Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue affects Envato Elements: from n/a through 2.0.14.... Read more
Affected Products : envato_elements- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2024-56274
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through 1.2.15.... Read more
Affected Products : astra_widgets- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-56273
Missing Authorization vulnerability in WPvivid Backup & Migration WPvivid Backup and Migration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPvivid Backup and Migration: from n/a through 0.9.106.... Read more
Affected Products : migration\,_backup\,_staging- Published: Jan. 07, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-56271
Missing Authorization vulnerability in SecureSubmit WP SecureSubmit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SecureSubmit: from n/a through 1.5.16.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
8.5
HIGHCVE-2024-51715
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link Pages allows Blind SQL Injection.This issue affects Cli... Read more
Affected Products : clickwhale- Published: Jan. 07, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2024-51700
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 김 민준 (Minjun Kim) NAVER Analytics allows Stored XSS.This issue affects NAVER Analytics: from n/a through 0.9.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.3
MEDIUMCVE-2024-51651
Missing Authorization vulnerability in CubeWP CubeWP Forms – All-in-One Form Builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CubeWP Forms – All-in-One Form Builder: from n/a through 1.1.5.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
9.8
CRITICALCVE-2024-49649
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Abdul Hakeem Build App Online allows PHP Local File Inclusion.This issue affects Build App Online: from n/a through 1.0.23.... Read more
- Published: Jan. 07, 2025
- Modified: Feb. 05, 2025
- Vuln Type: Path Traversal