Latest CVE Feed
-
6.5
MEDIUMCVE-2024-7747
The Wallet for WooCommerce plugin for WordPress is vulnerable to incorrect conversion between numeric types in all versions up to, and including, 1.5.6. This is due to a numerical logic flaw when transferring funds to another user. This makes it possible ... Read more
Affected Products : terawallet- Published: Nov. 28, 2024
- Modified: Jul. 15, 2025
-
6.5
MEDIUMCVE-2024-53731
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fintelligence Fintelligence Calculator allows Stored XSS.This issue affects Fintelligence Calculator: from n/a through 1.0.3.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.5
MEDIUMCVE-2024-8308
A low privileged remote attacker can insert a SQL injection in the web application due to improper handling of HTTP request input data which allows to exfiltrate all data.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
6.5
MEDIUMCVE-2024-53737
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Mailster allows Stored XSS.This issue affects WP Mailster: from n/a through 1.8.16.0.... Read more
Affected Products : wp_mailster- Published: Nov. 28, 2024
- Modified: Feb. 10, 2025
-
7.1
HIGHCVE-2024-53736
Cross-Site Request Forgery (CSRF) vulnerability in Jason Grim Custom Shortcode Sidebars allows Stored XSS.This issue affects Custom Shortcode Sidebars: from n/a through 1.2.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-53734
Cross-Site Request Forgery (CSRF) vulnerability in Idealien Studios Idealien Category Enhancements allows Stored XSS.This issue affects Idealien Category Enhancements: from n/a through 1.2.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-53733
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rohit Harsh Fence URL allows Stored XSS.This issue affects Fence URL: from n/a through 2.0.0.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-53732
Cross-Site Request Forgery (CSRF) vulnerability in WP WOX Footer Flyout Widget allows Stored XSS.This issue affects Footer Flyout Widget: from n/a through 1.1.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52501
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in webbytemplate Office Locator.This issue affects Office Locator: from n/a through 1.3.0.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52499
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Kardi Pricing table addon for elementor allows PHP Local File Inclusion.This issue affects Pricing table addon for elementor: from n/a... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52498
Path Traversal: '.../...//' vulnerability in Softpulse Infotech SP Blog Designer allows PHP Local File Inclusion.This issue affects SP Blog Designer: from n/a through 1.0.0.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52497
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in quomodosoft Shopready allows PHP Local File Inclusion.This issue affects Shopready: from n/a through 3.5.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52496
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AbsolutePlugins Absolute Addons For Elementor allows Local Code Inclusion.This issue affects Absolute Addons For Elementor: from n/a t... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
8.5
HIGHCVE-2024-52495
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Eniture Technology Distance Based Shipping Calculator allows SQL Injection.This issue affects Distance Based Shipping Calculator: from n/a through 2.0.21... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
10.0
CRITICALCVE-2024-52490
Unrestricted Upload of File with Dangerous Type vulnerability in Pathomation allows Upload a Web Shell to a Web Server.This issue affects Pathomation: from n/a through 2.5.1.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.5
HIGHCVE-2024-52481
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Astoundify Jobify - Job Board WordPress Theme allows Relative Path Traversal.This issue affects Jobify - Job Board WordPress Theme: from n/a through 4.2.3.... Read more
Affected Products : jobify- Published: Nov. 28, 2024
- Modified: Feb. 10, 2025
-
9.8
CRITICALCVE-2024-52475
Authentication Bypass Using an Alternate Path or Channel vulnerability in Automation Web Platform Wawp allows Authentication Bypass.This issue affects Wawp: from n/a before 3.0.18.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
9.3
CRITICALCVE-2024-52474
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LLC «TriIncom» Express Payments Module allows Blind SQL Injection.This issue affects Express Payments Module: from n/a through 1.1.8.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.2
HIGHCVE-2024-11620
Improper Control of Generation of Code ('Code Injection') vulnerability in Rank Math SEO allows Code Injection.This issue affects Rank Math SEO: from n/a through 1.0.231.... Read more
Affected Products : seo- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024
-
7.1
HIGHCVE-2024-11402
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP-speedup Block Editor Bootstrap Blocks allows Reflected XSS.This issue affects Block Editor Bootstrap Blocks: from n/a through 6.6.1.... Read more
Affected Products :- Published: Nov. 28, 2024
- Modified: Nov. 28, 2024