Latest CVE Feed
-
7.5
HIGHCVE-2024-8009
The Sensei LMS WordPress plugin before 4.20.0 disclose all users of the blog including their email address to teachers on the students page... Read more
Affected Products : sensei_lms- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Information Disclosure
-
4.3
MEDIUMCVE-2024-7984
The Joy Of Text Lite WordPress plugin through 2.3.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2024-7769
The ClickSold IDX WordPress plugin through 1.90 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : clicksold_idx- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-7762
The Simple Job Board WordPress plugin before 2.12.6 does not prevent uploaded files from being listed, allowing unauthenticated users to access and download uploaded resumes... Read more
Affected Products : simple_job_board- Published: May. 15, 2025
- Modified: Aug. 29, 2025
- Vuln Type: Information Disclosure
-
6.1
MEDIUMCVE-2024-7761
In the process of testing the Simple Job Board WordPress plugin before 2.12.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which entails account takeover backdoor... Read more
Affected Products : simple_job_board- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-7759
The PWA for WP WordPress plugin before 1.7.72 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products : pwa_for_wp_\&_amp- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-7758
The Stylish Price List WordPress plugin before 7.1.8 does not sanitise and escape some of its settings, which could allow high privilege users of contributor and above to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabilit... Read more
Affected Products : stylish_price_list- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-7556
The Simple Share WordPress plugin through 0.5.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (... Read more
Affected Products : simple_share- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2024-6809
The Simple Video Directory WordPress plugin before 1.4.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL injection.... Read more
Affected Products : simple_video_directory- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-6798
The DL Verification WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed ... Read more
Affected Products : dl_verification- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-6797
The DL Robots.txt WordPress plugin through 1.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (f... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 20, 2025
- Vuln Type: Cross-Site Scripting
-
8.1
HIGHCVE-2024-6719
The Offload Videos WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow low privilege users to update them via a CSRF attack... Read more
Affected Products :- Published: May. 15, 2025
- Modified: May. 20, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.4
MEDIUMCVE-2024-6718
The PVN Auth Popup WordPress plugin through 1.0.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform... Read more
Affected Products : pvn_auth_popup- Published: May. 15, 2025
- Modified: May. 27, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-6713
The PVN Auth Popup WordPress plugin through 1.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : pvn_auth_popup- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-6712
The MapFig Studio WordPress plugin through 0.2.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack... Read more
Affected Products : mapfig_studio- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Request Forgery
-
6.1
MEDIUMCVE-2024-6711
The Event Tickets with Ticket Scanner WordPress plugin before 2.3.8 does not sanitise and escape some parameters, which could allow users with a role as low as admin to perform Cross-Site Scripting attacks... Read more
Affected Products : event_tickets_with_ticket_scanner- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-6708
The User Profile Builder WordPress plugin before 3.12.2 does not sanitise and escape some parameters before outputting its content on the admin area, which allows Admin+ users to perform Cross-Site Scripting attacks.... Read more
Affected Products : profile_builder- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-6693
The wccp-pro WordPress plugin before 15.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : wp_content_copy_protection_\&_no_right_click- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-6690
The wccp-pro WordPress plugin before 15.3 contains an open-redirect flaw via the referrer parameter, allowing redirection of users to external sites... Read more
Affected Products : wp_content_copy_protection_\&_no_right_click- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Misconfiguration
-
5.4
MEDIUMCVE-2024-6668
The ProfilePro WordPress plugin through 1.3 does not sanitise and escape some parameters and lacks proper access controls, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks... Read more
Affected Products : profilepro- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting