Latest CVE Feed
-
4.3
MEDIUMCVE-2024-8902
The Elementor Addon Elements plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.8 via the render_column function in modules/data-table/widgets/data-table.php. This makes it possible for authenti... Read more
- Published: Oct. 12, 2024
- Modified: Jan. 16, 2025
-
7.2
HIGHCVE-2024-8757
The WP Post Author – Boost Your Blog's Engagement with Author Box, Social Links, Co-Authors, Guest Authors, Post Rating System, and Custom User Registration Form Builder plugin for WordPress is vulnerable to time-based SQL Injection via the linked_us... Read more
Affected Products : wp_post_author- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9696
The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 due to insufficient input sanitization and output escaping on user supplied attribute... Read more
Affected Products : rescue_shortcodes- Published: Oct. 12, 2024
- Modified: Nov. 25, 2024
-
6.4
MEDIUMCVE-2024-9595
The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to insufficient input sanitization and output escaping. This makes ... Read more
Affected Products : tablepress- Published: Oct. 12, 2024
- Modified: Aug. 09, 2025
-
6.4
MEDIUMCVE-2024-8915
The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attac... Read more
Affected Products :- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
5.3
MEDIUMCVE-2024-8760
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers to embed untrusted style information into comments resulti... Read more
Affected Products : stackable- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
4.3
MEDIUMCVE-2024-9756
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in versions 2.0 to 2.4.1. This makes it possible for authentic... Read more
Affected Products : order_attachments_for_woocommerce- Published: Oct. 12, 2024
- Modified: Nov. 25, 2024
-
6.4
MEDIUMCVE-2024-9704
The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including, 1.3.7 due to insufficient input sanitization and output escaping on user ... Read more
Affected Products : social_sharing- Published: Oct. 12, 2024
- Modified: Nov. 25, 2024
-
9.8
CRITICALCVE-2024-9047
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originall... Read more
Affected Products : wordpress_file_upload- Published: Oct. 12, 2024
- Modified: Mar. 12, 2025
-
4.3
MEDIUMCVE-2024-9824
The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'ip_delete_post' and 'ip_update_post_title' functions in all versions up to, and including, 1.2.2. Thi... Read more
Affected Products : imagepress- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
4.3
MEDIUMCVE-2024-9778
The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on the 'imagepress_admin_page' function. This makes it possib... Read more
Affected Products : imagepress- Published: Oct. 12, 2024
- Modified: Nov. 25, 2024
-
4.8
MEDIUMCVE-2024-9776
The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenti... Read more
Affected Products : imagepress- Published: Oct. 12, 2024
- Modified: Nov. 25, 2024
-
6.1
MEDIUMCVE-2024-9670
The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 6.0.2. This makes it possible for unauthenticated attackers... Read more
Affected Products :- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
6.4
MEDIUMCVE-2024-9656
The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated ... Read more
Affected Products :- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
4.3
MEDIUMCVE-2024-9187
The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteRm() function in all versions up to, and including, 1.1.8. This makes it possible for authenticated attackers, with Subscr... Read more
Affected Products :- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
4.4
MEDIUMCVE-2024-7489
The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form color parameters in all versions up to, and including, 2.5.6 due to insufficient input sanitization and output e... Read more
Affected Products : forms_for_mailchimp_by_optin_cat- Published: Oct. 12, 2024
- Modified: Oct. 16, 2024
-
6.5
MEDIUMCVE-2024-9860
The Bridge Core plugin for WordPress is vulnerable to unauthorized modification of data or loss of data due to a missing capability check on the 'import_action' and 'install_plugin_per_demo' functions in versions up to, and including, 3.3. This makes it p... Read more
Affected Products :- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
8.8
HIGHCVE-2024-9821
The Bot for Telegram on WooCommerce plugin for WordPress is vulnerable to sensitive information disclosure due to missing authorization checks on the 'stm_wpcfto_get_settings' AJAX action in all versions up to, and including, 1.2.4. This makes it possible... Read more
Affected Products :- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
6.1
MEDIUMCVE-2024-9592
The Easy PayPal Gift Certificate plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.2.3. This is due to missing or incorrect nonce validation on the 'wpppgc_plugin_options' function. This makes it possible... Read more
Affected Products :- Published: Oct. 12, 2024
- Modified: Oct. 15, 2024
-
7.2
HIGHCVE-2024-45754
An issue was discovered in the centreon-bi-server component in Centreon BI Server 24.04.x before 24.04.3, 23.10.x before 23.10.8, 23.04.x before 23.04.11, and 22.10.x before 22.10.11. SQL injection can occur in the listing of configured reporting jobs. Ex... Read more
Affected Products : centreon- Published: Oct. 11, 2024
- Modified: Oct. 15, 2024