Medium - CVE-2025-0805 - The Mortgage Calculator / Loan Calculator...
The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mlcalc' shortcode in all versions up to, and including,...
High - CVE-2024-13315 - The Shopwarden – Automated WooCommerce...
The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.11. This is due to missing or...
Medium - CVE-2024-13438 - The SpeedSize Image & Video AI-Optimizer plugin...
The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce...
High - CVE-2024-13556 - The Affiliate Links: WordPress Plugin for Link...
The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via...
NA - CVE-2024-45320 - Out-of-bounds write vulnerability exists in...
Out-of-bounds write vulnerability exists in DocuPrint CP225w 01.22.01 and earlier, DocuPrint CP228w 01.22.01 and earlier, DocuPrint CM225fw 01.10.01 and earlier, and DocuPrint CM228fw 01.10.01 and...
Medium - CVE-2024-13523 - The MemorialDay plugin for WordPress is...
The MemorialDay plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.4. This is due to missing or incorrect nonce validation on a function....
NA - CVE-2024-57963 - Insecure Loading of Dynamic Link Libraries have...
Insecure Loading of Dynamic Link Libraries have been discovered in USB-CONVERTERCABLE DRIVER, which could allow local attackers to potentially disclose information or execute arbitray code on...
NA - CVE-2024-57964 - Insecure Loading of Dynamic Link Libraries have...
Insecure Loading of Dynamic Link Libraries have been discovered in HVAC Energy Saving Program, which could allow local attackers to potentially disclose information or execute arbitray code on...
Medium - CVE-2024-11376 - The s2Member – Excellent for All Kinds of...
The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use...
Medium - CVE-2024-11895 - The Online Payments – Get Paid with PayPal,...
The Online Payments – Get Paid with PayPal, Square & Stripe plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including,...