Latest CVE Feed
-
6.5
MEDIUMCVE-2024-8308
A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.5
MEDIUMCVE-2024-53737
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Mailster allows Stored XSS.This issue affects WP Mailster: from n/a through 1.8.16.0.... Read more
Affected Products : wp_mailster- Published: Nov. 28, 2024
- Modified: Feb. 10, 2025
-
7.1
HIGHCVE-2024-53736
Cross-Site Request Forgery (CSRF) vulnerability in Jason Grim Custom Shortcode Sidebars allows Stored XSS.This issue affects Custom Shortcode Sidebars: from n/a through 1.2.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-53734
Cross-Site Request Forgery (CSRF) vulnerability in Idealien Studios Idealien Category Enhancements allows Stored XSS.This issue affects Idealien Category Enhancements: from n/a through 1.2.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-53733
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rohit Harsh Fence URL allows Stored XSS.This issue affects Fence URL: from n/a through 2.0.0.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-53732
Cross-Site Request Forgery (CSRF) vulnerability in WP WOX Footer Flyout Widget allows Stored XSS.This issue affects Footer Flyout Widget: from n/a through 1.1.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52501
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in webbytemplate Office Locator.This issue affects Office Locator: from n/a through 1.3.0.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52499
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kardi Pricing table addon for elementor allows PHP Local File Inclusion.This issue affects Pricing table addon for elementor: from n/a... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52498
Path Traversal: '.../...//' vulnerability in Softpulse Infotech SP Blog Designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through 1.0.0.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52497
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in quomodosoft Shopready allows PHP Local File Inclusion.This issue affects Shopready: from n/a through 3.5.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52496
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AbsolutePlugins Absolute Addons For Elementor allows Local Code Inclusion.This issue affects Absolute Addons For Elementor: from n/a t... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
8.5
HIGHCVE-2024-52495
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology Distance Based Shipping Calculator allows SQL Injection.This issue affects Distance Based Shipping Calculator: from n/a through 2.0.21... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
10.0
CRITICALCVE-2024-52490
Unrestricted Upload of File with Dangerous Type vulnerability in Pathomation allows Upload a Web Shell to a Web Server.This issue affects Pathomation: from n/a through 2.5.1.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52481
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify - Job Board WordPress Theme allows Relative Path Traversal.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.... Read more
Affected Products : jobify- Published: Nov. 28, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-52475
Authentication Bypass Using an Alternate Path or Channel vulnerability in Automation Web Platform Wawp allows Authentication Bypass.This issue affects Wawp: from n/a before 3.0.18.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
9.3
CRITICALCVE-2024-52474
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LLC «TriIncom» Express Payments Module allows Blind SQL Injection.This issue affects Express Payments Module: from n/a through 1.1.8.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.2
HIGHCVE-2024-11620
Improper Control of Generation of Code ('Code Injection') vulnerability in Rank Math SEO allows Code Injection.This issue affects Rank Math SEO: from n/a through 1.0.231.... Read more
Affected Products : seo- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-11402
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-speedup Block Editor Bootstrap Blocks allows Reflected XSS.This issue affects Block Editor Bootstrap Blocks: from n/a through 6.6.1.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
9.9
CRITICALCVE-2024-8672
The Widget Options – The #1 WordPress Widget & Block Control Plugin plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.7 via the display logic functionality that extends several page builders. This is due... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
5.7
MEDIUMCVE-2024-52283
Missing sanitation of inputs allowed arbitrary users to conduct a stored XSS attack that triggers for users that view a certain project... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024