Medium - CVE-2024-11335 - The UltraEmbed – Advanced Iframe Plugin For...
The UltraEmbed – Advanced Iframe Plugin For WordPress with Gutenberg Block Included plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframe'...
Medium - CVE-2024-11753 - The UMich OIDC Login plugin for WordPress is...
The UMich OIDC Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'umich_oidc_button' shortcode in all versions up to, and including, 1.2.0 due...
Medium - CVE-2024-11778 - The CanadaHelps Embedded Donation Form plugin...
The CanadaHelps Embedded Donation Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embedcdn' shortcode in all versions up to, and including,...
Medium - CVE-2024-12069 - The Lexicata plugin for WordPress is vulnerable...
The Lexicata plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including,...
Medium - CVE-2024-12339 - The Digihood HTML Sitemap plugin for WordPress...
The Digihood HTML Sitemap plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘channel' parameter in all versions up to, and including, 3.1.1 due to insufficient input...
Medium - CVE-2024-12522 - The Yay! Forms | Embed Custom Forms, Surveys,...
The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yayforms' shortcode in all...
Medium - CVE-2024-13390 - The ADFO – Custom data in admin dashboard...
The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adfo_list' shortcode in all versions up to, and...
Medium - CVE-2024-13405 - The Apptivo Business Site CRM plugin for...
The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-13462 - The WP Wiki Tooltip plugin for WordPress is...
The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode in all versions up to, and including, 2.0.2 due to...