Critical - CVE-2024-13725 - The Keap Official Opt-in Forms plugin for...
The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possible for...
Medium - CVE-2024-13848 - The Reaction Buttons plugin for WordPress is...
The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.6 due to insufficient input sanitization and...
High - CVE-2024-13852 - The Option Editor plugin for WordPress is...
The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the plugin_page() function. This makes it possible for...
Medium - CVE-2025-0796 - The Mortgage Lead Capture System plugin for...
The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.10. This is due to missing or incorrect nonce validation...
Medium - CVE-2025-0805 - The Mortgage Calculator / Loan Calculator...
The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mlcalc' shortcode in all versions up to, and including,...
High - CVE-2024-13315 - The Shopwarden – Automated WooCommerce...
The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.11. This is due to missing or...
Medium - CVE-2024-13438 - The SpeedSize Image & Video AI-Optimizer plugin...
The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce...
High - CVE-2024-13556 - The Affiliate Links: WordPress Plugin for Link...
The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via...
NA - CVE-2024-45320 - Out-of-bounds write vulnerability exists in...
Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier, DocuPrint CM225fw 01.10.01 and earlier, and DocuPrint CM228fw 01.10.01 and...
Medium - CVE-2024-13523 - The MemorialDay plugin for WordPress is...
The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on a function....