Latest CVE Feed
-
8.1
HIGHCVE-2024-11721
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.24.5. This is due to insufficient controls on the user role select field when utilizing the 'Role' field in a form. This ma... Read more
Affected Products : frontend_admin- Published: Dec. 14, 2024
- Modified: Jun. 05, 2025
-
7.2
HIGHCVE-2024-11720
The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via submission forms in all versions up to, and including, 3.24.5 due to insufficient input sanitization and output escaping on the new Taxonomy form. This ... Read more
Affected Products : frontend_admin- Published: Dec. 14, 2024
- Modified: Jun. 05, 2025
-
4.4
MEDIUMCVE-2024-12628
The bodi0`s Easy cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cache-folder' parameter in all versions up to, and including, 0.8 due to insufficient input sanitization and output escaping. This makes it possible for auth... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-12446
The Post to Pdf plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gmptp_single_post' shortcode in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attribut... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
9.8
CRITICALCVE-2024-11715
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the assignUserRole() function in all versions up to, and including, 2.2.2. Th... Read more
Affected Products : wp_job_portal- Published: Dec. 14, 2024
- Modified: Feb. 06, 2025
-
4.9
MEDIUMCVE-2024-11714
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'ff' parameter of the getFieldsForVisibleCombobox() function in all versions up to, and including, 2.2.2 due to ... Read more
Affected Products : wp_job_portal- Published: Dec. 14, 2024
- Modified: Feb. 06, 2025
-
4.9
MEDIUMCVE-2024-11713
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'page_id' parameter of the wpjobportal_deactivate() function in all versions up to, and including, 2.2.2 due to ... Read more
Affected Products : wp_job_portal- Published: Dec. 14, 2024
- Modified: Feb. 06, 2025
-
5.3
MEDIUMCVE-2024-11712
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the getResumeFileDownloadById() function in all versions up to, and i... Read more
Affected Products : wp_job_portal- Published: Dec. 14, 2024
- Modified: Feb. 05, 2025
-
7.5
HIGHCVE-2024-11711
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'resumeid' parameter in all versions up to, and including, 2.2.1 due to insufficient escaping on the user suppli... Read more
Affected Products : wp_job_portal- Published: Dec. 14, 2024
- Modified: Feb. 05, 2025
-
4.9
MEDIUMCVE-2024-11710
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'fieldfor', 'visibleParent' and 'id' parameters in all versions up to, and including, 2.2.2 due to insufficient ... Read more
Affected Products : wp_job_portal- Published: Dec. 14, 2024
- Modified: Feb. 05, 2025
-
6.4
MEDIUMCVE-2024-12501
The Simple Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-12474
The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output esc... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-12459
The Ganohrs Toggle Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggle' shortcode in all versions up to, and including, 0.2.4 due to insufficient input sanitization and output escaping on user supplied attr... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.1
MEDIUMCVE-2024-12422
The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient input sanitization and output escaping. This makes it possible for u... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.4
MEDIUMCVE-2024-11752
The Eveeno plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eveeno' shortcode in all versions up to, and including, 1.7 due to insufficient input sanitization and output escaping on user supplied attributes. This makes i... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
4.3
MEDIUMCVE-2024-10690
The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.4 via the 'SHORTCODE_ELEMENTOR' shortcode due to insufficient restrictions on which posts can be included. This makes it poss... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
7.2
HIGHCVE-2024-10646
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in all versions up to, and including, 5.2.6 due to insufficient in... Read more
Affected Products : contact_form- Published: Dec. 14, 2024
- Modified: Feb. 06, 2025
-
7.2
HIGHCVE-2024-9698
The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_files' function in all versions up to, and including, 3.3. This makes it possible for authenticated attack... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
5.3
MEDIUMCVE-2024-12578
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' endpoint. This makes it possible for unauthenticated attackers to extract sensi... Read more
Affected Products : tickera- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024
-
6.1
MEDIUMCVE-2024-12555
The SIP Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on a function. This makes it possible for unauthenticated attackers to inject malicious ... Read more
Affected Products :- Published: Dec. 14, 2024
- Modified: Dec. 14, 2024