Medium - CVE-2024-10623 - The ForumEngine theme for WordPress is...
The ForumEngine theme for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping....
Medium - CVE-2024-10671 - The Button Block – Get fully customizable &...
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.4 via the [btn_block]...
Medium - CVE-2024-10675 - The affiliate-toolkit plugin for WordPress is...
The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 3.6.7 due to insufficient input sanitization and output...
Medium - CVE-2024-10682 - The Announcement & Notification Banner –...
The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg and remove_query_arg without appropriate...
Medium - CVE-2024-10726 - The Friendly Functions for Welcart plugin for...
The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation...
Medium - CVE-2024-10782 - The Theme Builder For Elementor plugin for...
The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the 'elementor-template' shortcode due to...
Medium - CVE-2024-10785 - The Gutenberg Blocks with AI by Kadence WP –...
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Countdown' widget in all versions up to, and...
High - CVE-2024-10788 - The Activity Log – Monitor & Record User...
The Activity Log – Monitor & Record User Changes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the event parameters in all versions up to, and including, 2.11.1 due to...
Medium - CVE-2024-10792 - The Easiest Funnel Builder For WordPress &...
The Easiest Funnel Builder For WordPress & WooCommerce by WPFunnels plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'post_id' parameter in all versions up to,...