Latest CVE Feed
-
6.1
MEDIUMCVE-2024-4002
The Carousel, Slider, Gallery by WP Carousel WordPress plugin before 2.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_htm... Read more
Affected Products : carousel\,_slider\,_gallery_by_wp_carousel- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-3996
The Smart Post Show WordPress plugin before 2.4.28 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallow... Read more
Affected Products : smart_post_show- Published: May. 15, 2025
- Modified: Jun. 04, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-3901
The Genesis Blocks WordPress plugin through 3.1.3 does not properly escape attributes provided to some of its custom blocks, making it possible for users allowed to write posts (like those with the contributor role) to conduct Stored XSS attacks.... Read more
Affected Products : genesis_blocks- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-3062
The Save as Image Plugin by Pdfcrowd WordPress plugin before 3.2.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabil... Read more
Affected Products : save_as_pdf- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-2869
The Easy Property Listings WordPress plugin before 3.5.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : easy_property_listings- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-2643
The Floating Notification Bar, Sticky Menu on Scroll, Announcement Banner, and Sticky Header for Any WordPress plugin before 2.6.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored ... Read more
Affected Products : my_sticky_bar- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-1663
The Ultimate Noindex Nofollow Tool II WordPress plugin before 1.3.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capabi... Read more
Affected Products : ultimate_noindex_nofollow_tool_ii- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13865
The S3Player WordPress plugin through 4.2.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.... Read more
Affected Products : s3player- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13828
The Badgearoo WordPress plugin through 1.0.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : badgearoo- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13823
The 360 Product Rotation WordPress plugin through 1.5.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.... Read more
Affected Products : 360_product_rotation- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13730
The Podlove Podcast Publisher WordPress plugin before 4.2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ... Read more
Affected Products : podlove_podcast_publisher- Published: May. 15, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13729
The Podlove Podcast Publisher WordPress plugin before 4.1.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is... Read more
Affected Products : podlove_podcast_publisher- Published: May. 15, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13727
The MemberSpace WordPress plugin before 2.1.14 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against only unauthenticated users.... Read more
Affected Products : memberspace- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13621
The GDPR Framework By Data443 WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is ... Read more
Affected Products : gdpr_framework- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-13619
The LifterLMS WordPress plugin before 8.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : lifterlms- Published: May. 15, 2025
- Modified: Jun. 10, 2025
-
4.8
MEDIUMCVE-2024-13616
The VikBooking Hotel Booking Engine & PMS WordPress plugin before 1.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html ca... Read more
Affected Products : vikbooking_hotel_booking_engine_\&_pms- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13486
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : icegram_engage- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13482
The Icegram Engage WordPress plugin before 3.1.32 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowe... Read more
Affected Products : icegram_engage- Published: May. 15, 2025
- Modified: May. 28, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13384
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.24 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfi... Read more
Affected Products : robo_gallery- Published: May. 15, 2025
- Modified: Jun. 05, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13383
The HD Quiz WordPress plugin before 2.0.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ex... Read more
Affected Products : hd_quiz- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting