Critical - CVE-2024-12822 - The Media Manager for UserPro plugin for...
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the add_capto_img()...
Medium - CVE-2024-12861 - The W2S – Migrate WooCommerce to Shopify plugin...
The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via the 'viw2s_view_log' AJAX action. This...
Medium - CVE-2024-13349 - The Stockdio Historical Chart plugin for...
The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockdio-historical-chart' shortcode in all versions up to, and...
Medium - CVE-2024-13400 - The Kona Gallery Block plugin for WordPress is...
The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gutenberg" Block, specifically in the "align" attribute, in all versions up to,...
Medium - CVE-2024-13460 - The WE – Testimonial Slider plugin for...
The WE – Testimonial Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Testimonial Author Names in all versions up to, and including, 1.5 due to insufficient input...
Medium - CVE-2024-13512 - The Wonder FontAwesome plugin for WordPress is...
The Wonder FontAwesome plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.8. This is due to missing or incorrect nonce validation on one of its...
Medium - CVE-2024-13549 - The All Bootstrap Blocks plugin for WordPress...
The All Bootstrap Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Accordion" widget in all versions up to, and including, 1.3.26 due to insufficient input...
Medium - CVE-2024-13596 - The WordPress Survey & Poll – Quiz, Survey and...
The WordPress Survey & Poll – Quiz, Survey and Poll Plugin for WordPress plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'survey' shortcode in...
High - CVE-2024-13646 - The Single-user-chat plugin for WordPress is...
The Single-user-chat plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to insufficient validation on the...
Medium - CVE-2024-13652 - The ECPay Ecommerce for WooCommerce plugin for...
The ECPay Ecommerce for WooCommerce plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'clear_ecpay_debug_log' AJAX action in all...