Latest CVE Feed
-
4.8
MEDIUMCVE-2024-13382
The Calculated Fields Form WordPress plugin before 5.2.64 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is di... Read more
Affected Products : calculated_fields_form- Published: May. 15, 2025
- Modified: May. 23, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13357
The Ditty WordPress plugin before 3.1.52 does not sanitise and escape some of its settings, which could allow high privilege users such as author to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for e... Read more
Affected Products : ditty- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13313
The AWeber WordPress plugin through 7.3.20 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ... Read more
Affected Products : aweber- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13128
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : learnpress- Published: May. 15, 2025
- Modified: May. 22, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13127
The LearnPress WordPress plugin before 4.2.7.5.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed... Read more
Affected Products : learnpress- Published: May. 15, 2025
- Modified: May. 22, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-13053
The Form Maker by 10Web WordPress plugin before 1.15.33 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is dis... Read more
Affected Products : form_maker- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-12874
The Top Comments WordPress plugin through 1.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (fo... Read more
Affected Products : top_comments- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12873
The Custom Field Manager WordPress plugin through 1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : custom_field_manager- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-12812
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 is affected by an IDOR issue where employees can manipulate parameters to access the data of terminated employees.... Read more
Affected Products : wp_erp- Published: May. 15, 2025
- Modified: Aug. 22, 2025
- Vuln Type: Authorization
-
4.8
MEDIUMCVE-2024-12808
The WP ERP | Complete HR solution with recruitment & job listings | WooCommerce CRM & Accounting WordPress plugin before 1.13.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross... Read more
Affected Products : wp_erp- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-12800
The IP Based Login WordPress plugin before 2.4.1 does not sanitise values when importing, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for examp... Read more
Affected Products : ip_based_login- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-12770
The WP ULike WordPress plugin before 4.7.6 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ... Read more
Affected Products : wp_ulike- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
7.5
HIGHCVE-2024-12767
The buddyboss-platform WordPress plugin before 2.7.60 lacks proper access controls and allows a logged-in user to view comments on private posts... Read more
Affected Products : buddyboss_platform- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Authorization
-
4.3
MEDIUMCVE-2024-12750
The Competition Form WordPress plugin through 2.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack... Read more
Affected Products : competition_form- Published: May. 15, 2025
- Modified: Jun. 09, 2025
- Vuln Type: Cross-Site Request Forgery
-
4.8
MEDIUMCVE-2024-12743
The MailPoet WordPress plugin before 5.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for ... Read more
Affected Products : mailpoet- Published: May. 15, 2025
- Modified: Jun. 10, 2025
- Vuln Type: Cross-Site Scripting
-
4.8
MEDIUMCVE-2024-12739
The Mobile Contact Bar WordPress plugin before 3.0.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallo... Read more
Affected Products : mobile_contact_bar- Published: May. 15, 2025
- Modified: Jun. 11, 2025
- Vuln Type: Cross-Site Scripting
-
7.2
HIGHCVE-2024-12735
The Advance Post Prefix WordPress plugin through 1.1.1 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins and above to perform SQL injection attacks... Read more
Affected Products : advance_post_prefix- Published: May. 15, 2025
- Modified: May. 22, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2024-12734
The Advance Post Prefix WordPress plugin through 1.1.1, Advance Post Prefix WordPress plugin through 1.1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used agai... Read more
Affected Products : advance_post_prefix- Published: May. 15, 2025
- Modified: May. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12733
The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : affiliateimportereb- Published: May. 15, 2025
- Modified: May. 22, 2025
- Vuln Type: Cross-Site Scripting
-
6.1
MEDIUMCVE-2024-12732
The AffiliateImporterEb WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.... Read more
Affected Products : affiliateimportereb- Published: May. 15, 2025
- Modified: May. 22, 2025
- Vuln Type: Cross-Site Scripting