Medium - CVE-2024-13398 - The Checkout for PayPal plugin for WordPress is...
The Checkout for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'checkout_for_paypal' shortcode in all versions up to, and including,...
Medium - CVE-2024-13401 - The Payment Button for PayPal plugin for...
The Payment Button for PayPal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_paypal_checkout' shortcode in all versions up to, and including,...
Medium - CVE-2024-13434 - The WP Inventory Manager plugin for WordPress...
The WP Inventory Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 2.3.2 due to insufficient...
Medium - CVE-2024-10799 - The Eventer plugin for WordPress is vulnerable...
The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_tickets() function. This makes it possible for...
NA - CVE-2024-11146 - TrueFiling is a collaborative, web-based...
TrueFiling is a collaborative, web-based electronic filing system where attorneys, paralegals, court reporters and self-represented filers collect public legal documentation into cases. TrueFiling...
High - CVE-2024-13333 - The Advanced File Manager plugin for WordPress...
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to...
Medium - CVE-2024-12203 - The RSS Icon Widget plugin for WordPress is...
The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in all versions up to, and including, 5.2 due to insufficient input sanitization...
Medium - CVE-2024-12466 - The Proofreading plugin for WordPress is...
The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.2.1.1 due to insufficient input...
Medium - CVE-2024-12508 - The Glofox Shortcodes plugin for WordPress is...
The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'glofox_lead_capture ' shortcodes in all versions up...
Medium - CVE-2024-12598 - The MyBookProgress by Stormhill Media plugin...
The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ parameter in all versions up to, and including, 1.0.8 due to insufficient...