High - CVE-2024-13468 - The Trash Duplicate and 301 Redirect plugin for...
The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all...
Medium - CVE-2024-13589 - The YouTube Playlists with Schema plugin for...
The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and including, 2.6.1...
Medium - CVE-2024-13591 - The Team Builder For WPBakery Page...
The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'team-builder-vc' shortcode in...
High - CVE-2024-13592 - The Team Builder For WPBakery Page...
The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the...
Medium - CVE-2024-13657 - The Store Locator Widget plugin for WordPress...
The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocatorwidget' shortcode in all versions up to, and including,...
Medium - CVE-2024-13660 - The Responsive Flickr Slideshow plugin for...
The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fshow' shortcode in all versions up to, and including, 2.6.1 due...
Medium - CVE-2024-13663 - The Coaching Staffs plugin for WordPress is...
The Coaching Staffs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mstw-cs-table' shortcode in all versions up to, and including, 1.4 due to...
Medium - CVE-2024-13674 - The Cosmic Blocks (40+) Content Editor Blocks...
The Cosmic Blocks (40+) Content Editor Blocks Collection plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cwp_social_share' shortcode in all...
Medium - CVE-2024-13676 - The Categorized Gallery Plugin plugin for...
The Categorized Gallery Plugin plugin for WordPress is vulnerable to SQL Injection via the 'field' attribute of the 'image_gallery' shortcode in all versions up to, and...
Medium - CVE-2024-13679 - The Widget BUY.BOX plugin for WordPress is...
The Widget BUY.BOX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buybox-widget' shortcode in all versions up to, and including, 3.1.5 due to...