High - CVE-2024-13654 - The ZoxPress - The All-In-One WordPress News...
The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on...
High - CVE-2024-13656 - The Click Mag - Viral WordPress News...
The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability...
Medium - CVE-2024-13658 - The NGG Smart Image Search plugin for WordPress...
The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and...
Medium - CVE-2024-13665 - The Admire Extra plugin for WordPress is...
The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in all versions up to, and including, 1.6 due to insufficient...
Medium - CVE-2024-13769 - The Puzzles | WP Magazine / Review with Store...
The Puzzles | WP Magazine / Review with Store WordPress Theme + RTL theme for WordPress is vulnerable to Stored Cross-Site Scripting due to a missing capability check on the...
High - CVE-2024-13800 - The ConvertPlus plugin for WordPress is...
The ConvertPlus plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the 'cp_dismiss_notice'...
Medium - CVE-2024-13374 - The WP Table Manager plugin for WordPress is...
The WP Table Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on thewptm_getFolders AJAX action in all versions up to, and including, 4.1.3. This...
High - CVE-2024-13600 - The Majestic Support – The Leading-Edge Help...
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.5 via the...
Medium - CVE-2024-13601 - The Majestic Support – The Leading-Edge Help...
The Majestic Support – The Leading-Edge Help Desk & Customer Support Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.0.5 via...
High - CVE-2024-13714 - The All-Images.ai – IA Image Bank and Custom...
The All-Images.ai – IA Image Bank and Custom Image creation plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the '_get_image_by_url'...