Latest CVE Feed
-
6.4
MEDIUMCVE-2024-12502
The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-landing' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user suppl... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-12458
The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' shortcode in all versions up to, and including, 1.4.3 due to insufficient input sanitization and output escaping on user supplied attri... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-12448
The Posts and Products Views for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'papvfwc_views' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping ... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
4.3
MEDIUMCVE-2024-12447
The Get Post Content Shortcode plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 0.4 via the 'post-content' shortcode due to missing validation on a user controlled key. This makes it possible for... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.1
MEDIUMCVE-2024-12411
The WP Ad Guru – Banner ad, Responsive popup, Popup maker, Ad rotator & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 2.5.4 due to insufficient input sanitization and ... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11894
The The Permalinker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'permalink' shortcode in all versions up to, and including, 1.8.1 due to insufficient input sanitization and output escaping on user supplied attributes... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11889
The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-search' shortcode in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping on user suppli... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11888
The IDer Login for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ider_login_button' shortcode in all versions up to, and including, 2.1 due to insufficient input sanitization and output escaping on user supp... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11884
The Wp photo text slider 50 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp-photo-slider' shortcode in all versions up to, and including, 8.1 due to insufficient input sanitization and output escaping on user supplie... Read more
Affected Products : wp_photo_text_slider_50- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11883
The Connatix Video Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cnx_script_code' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11877
The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score' shortcode in all versions up to, and including, 2.0.2 due to insufficient input sanitization and output escaping on user supplied att... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11876
The Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'kredeum_opensky' shortcode in all versions up to, and including, 1.6.9 due to insuffici... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11873
The glomex oEmbed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glomex_integration' shortcode in all versions up to, and including, 0.9.1 due to insufficient input sanitization and output escaping on user supplied att... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11869
The Buk for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buk' shortcode in all versions up to, and including, 1.0.7 due to insufficient input sanitization and output escaping on user supplied attributes. Th... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11867
The Companion Portfolio – Responsive Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'companion-portfolio' shortcode in all versions up to, and including, 2.4.0.1 due to insufficient input sanitization a... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11865
The Tabs Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on tab descriptions. This makes it possible for authenticated attackers, with... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11855
The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. Thi... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11770
The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' shortcode in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping on user supplied attri... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11763
The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i... Read more
Affected Products : plezi- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11759
The Bukza plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bukza' shortcode in all versions up to, and including, 2.0.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024