Medium - CVE-2024-13578 - The WP-BibTeX plugin for WordPress is...
The WP-BibTeX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'WpBibTeX' shortcode in all versions up to, and including, 3.0.1 due to insufficient...
Medium - CVE-2024-13579 - The WP-Asambleas plugin for WordPress is...
The WP-Asambleas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'polls_popup' shortcode in all versions up to, and including, 2.85.0 due to...
Medium - CVE-2024-13581 - The Simple Charts plugin for WordPress is...
The Simple Charts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simple_chart' shortcode in all versions up to, and including, 1.0 due to...
Medium - CVE-2024-13582 - The Simple Pricing Tables For WPBakery Page...
The Simple Pricing Tables For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Medium - CVE-2024-13587 - The Zigaform – Price Calculator & Cost...
The Zigaform – Price Calculator & Cost Estimation Form Builder Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zgfm_fvar' shortcode in all...
Medium - CVE-2024-13588 - The Simplebooklet PDF Viewer and Embedder...
The Simplebooklet PDF Viewer and Embedder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'simplebooklet' shortcode in all versions up to, and...
Medium - CVE-2024-13595 - The Simple Signup Form plugin for WordPress is...
The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and including, 1.6.5 due to...
Medium - CVE-2024-13609 - The 1 Click WordPress Migration Plugin – 100%...
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1 via the...
High - CVE-2024-13622 - The File Uploads Addon for WooCommerce plugin...
The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the 'uploads' directory. This...
High - CVE-2024-13677 - The GetBookingsWP – Appointments Booking...
The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.27....