Latest CVE Feed
-
5.9
MEDIUMCVE-2024-56293
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nasirahmed Advanced Form Integration allows Stored XSS.This issue affects Advanced Form Integration: from n/a through 1.95.0.... Read more
Affected Products : advanced_form_integration- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2024-56292
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpdevelop, oplugins Email Reminders allows Stored XSS.This issue affects Email Reminders: from n/a through 2.0.5.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2024-56291
Deserialization of Untrusted Data vulnerability in plainware.com PlainInventory allows Object Injection.This issue affects PlainInventory: from n/a through 3.1.6.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2024-56290
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in silverplugins217 Multiple Shipping And Billing Address For Woocommerce allows SQL Injection.This issue affects Multiple Shipping And Billing Address For ... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
7.1
HIGHCVE-2024-56289
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Groundhogg Inc. Groundhogg allows Reflected XSS.This issue affects Groundhogg: from n/a through 3.7.3.3.... Read more
Affected Products : groundhogg- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Scripting
-
5.9
MEDIUMCVE-2024-56288
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fahad Mahmood WP Docs allows Stored XSS.This issue affects WP Docs: from n/a through 2.2.1.... Read more
Affected Products : wp_docs- Published: Jan. 07, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Cross-Site Scripting
-
6.5
MEDIUMCVE-2024-56287
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in biztechc WP jQuery DataTable allows Stored XSS.This issue affects WP jQuery DataTable: from n/a through 4.0.1.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-56286
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Classic Addons Classic Addons – WPBakery Page Builder allows PHP Local File Inclusion.This issue affects Classic Addons – WPBakery Page Builder: from n/a throu... Read more
Affected Products : page_builder- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Path Traversal
-
6.5
MEDIUMCVE-2024-56285
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPBits WPBITS Addons For Elementor Page Builder allows Stored XSS.This issue affects WPBITS Addons For Elementor Page Builder: from n/a through 1.5.1.... Read more
Affected Products : wpbits_addons_for_elementor_page_builder- Published: Jan. 07, 2025
- Modified: Mar. 04, 2025
- Vuln Type: Cross-Site Scripting
-
9.3
CRITICALCVE-2024-56284
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SSL Wireless SSL Wireless SMS Notification allows SQL Injection.This issue affects SSL Wireless SMS Notification: from n/a through 3.5.0.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
8.1
HIGHCVE-2024-56283
Deserialization of Untrusted Data vulnerability in plainware.com Locatoraid Store Locator allows Object Injection.This issue affects Locatoraid Store Locator: from n/a through 3.9.50.... Read more
Affected Products : locatoraid- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-56282
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elicus WPMozo Addons Lite for Elementor allows PHP Local File Inclusion.This issue affects WPMozo Addons Lite for Elementor: from n/a ... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-56281
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodeMShop 워드프레스 결제 심플페이 allows PHP Local File Inclusion.This issue affects 워드프레스 결제 심플페이: from n/a through 5.2.0.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-56280
Incorrect Privilege Assignment vulnerability in Amento Tech Pvt ltd WPGuppy allows Privilege Escalation.This issue affects WPGuppy: from n/a through 1.1.0.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Authorization
-
6.4
MEDIUMCVE-2024-56279
Server-Side Request Forgery (SSRF) vulnerability in Tips and Tricks HQ Compact WP Audio Player allows Server Side Request Forgery.This issue affects Compact WP Audio Player: from n/a through 1.9.14.... Read more
Affected Products : compact_wp_audio_player- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
9.1
CRITICALCVE-2024-56278
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP Ultimate Exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through 2.9.1.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-56276
Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a through 1.9.2.2.... Read more
- Published: Jan. 07, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Authorization
-
4.1
MEDIUMCVE-2024-56275
Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue affects Envato Elements: from n/a through 2.0.14.... Read more
Affected Products : envato_elements- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Server-Side Request Forgery
-
6.5
MEDIUMCVE-2024-56274
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a through 1.2.15.... Read more
Affected Products : astra_widgets- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-56273
Missing Authorization vulnerability in WPvivid Backup & Migration WPvivid Backup and Migration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPvivid Backup and Migration: from n/a through 0.9.106.... Read more
Affected Products : migration\,_backup\,_staging- Published: Jan. 07, 2025
- Modified: Feb. 25, 2025
- Vuln Type: Authorization