Latest CVE Feed
-
4.3
MEDIUMCVE-2024-11724
The Cookie Consent for WP – Cookie Consent, Consent Log, Cookie Scanner, Script Blocker (for GDPR, CCPA & ePrivacy) plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpl_script_save AJAX actio... Read more
Affected Products : wp_cookie_consent- Published: Dec. 12, 2024
- Modified: Jul. 14, 2025
-
4.3
MEDIUMCVE-2024-11181
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 9.9.9.3 via the 'wp_reusable_render' shortcode due to insufficient restrictions on which posts can be inclu... Read more
Affected Products : greenshift_-_animation_and_page_builder_blocks- Published: Dec. 12, 2024
- Modified: Jun. 05, 2025
-
6.4
MEDIUMCVE-2024-10784
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to, and including, 1.5.126 due to insufficient input sanitization and... Read more
Affected Products : unlimited_elements_for_elementor_\(free_widgets\,_addons\,_templates\)- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
5.4
MEDIUMCVE-2024-10583
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter in all versions up to, and including, 1.20.2 due to insuff... Read more
Affected Products : popup_maker- Published: Dec. 12, 2024
- Modified: Apr. 11, 2025
-
4.8
MEDIUMCVE-2024-9881
The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : learnpress- Published: Dec. 12, 2024
- Modified: May. 07, 2025
-
4.8
MEDIUMCVE-2024-9641
The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ... Read more
Affected Products : luckywp_table_of_contents- Published: Dec. 12, 2024
- Modified: May. 07, 2025
-
4.8
MEDIUMCVE-2024-9428
The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed ... Read more
Affected Products : popup_builder- Published: Dec. 12, 2024
- Modified: May. 07, 2025
-
5.3
MEDIUMCVE-2024-12265
The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/depay/wc/debug REST API endpoint in all versions up to, and including, 2.12.17. This make... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2024-12263
The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cloud_delete() and cloud_update() functions in all versions up to, and including, 1.5.5. This makes it pos... Read more
Affected Products : child_theme_creator- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
5.3
MEDIUMCVE-2024-12255
The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns phpinfo() data. This makes it possible for unauthenticated attack... Read more
Affected Products : accept_stripe_payments_using_contact_form_7- Published: Dec. 12, 2024
- Modified: Jul. 02, 2025
-
7.5
HIGHCVE-2024-12172
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpc_update_user_meta_option() function in all versions u... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
6.1
MEDIUMCVE-2024-12072
The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.2. This makes it possible... Read more
Affected Products : analytics_cat- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2024-12059
The ElementInvader Addons for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.1 via the eli_option_value shortcode. This makes it possible for authenticated attackers, with Contribut... Read more
Affected Products : elementinvader_addons_for_elementor- Published: Dec. 12, 2024
- Modified: Mar. 06, 2025
-
8.8
HIGHCVE-2024-12040
The Product Carousel Slider & Grid Ultimate for WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.9.10 via the 'theme' attribute of the `wcpcsu` shortcode. This makes it possible for authenticat... Read more
Affected Products : product_carousel_slider_\&_grid_ultimate_for_woocommerce- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
4.3
MEDIUMCVE-2024-12018
The Snippet Shortcodes plugin for WordPress is vulnerable to unauthorized Shortcode Deletion due to missing authorization in all versions up to, and including, 4.1.6. Note that a nonce is used as authentication here, but the value is leaked. This makes it... Read more
Affected Products : snippet_shortcodes- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
6.4
MEDIUMCVE-2024-11882
The FAQ And Answers – Create Frequently Asked Questions Area on WP Sites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'faq' shortcode in all versions up to, and including, 1.1.0 due to insufficient input sanitization ... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
6.4
MEDIUMCVE-2024-11871
The Social Media Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'patreon' shortcode in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping on user supplied attr... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
6.4
MEDIUMCVE-2024-11785
The Integrate Firebase plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'firebase_show' shortcode in all versions up to, and including, 0.9.3 due to insufficient input sanitization and output escaping on user supplied att... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
6.4
MEDIUMCVE-2024-11781
The Smart Agenda – Prise de rendez-vous en ligne plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'smartagenda' shortcode in all versions up to, and including, 4.6 due to insufficient input sanitization and output escapin... Read more
Affected Products :- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024
-
6.4
MEDIUMCVE-2024-11766
The WordPress Book Plugin for Displaying Books in Grid, Flip, Slider, Popup Layout and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gs_book_showcase' shortcode in all versions up to, and including, 1.3.1 due to ... Read more
Affected Products : gs_books_showcase- Published: Dec. 12, 2024
- Modified: Dec. 12, 2024