Medium - CVE-2024-12028 - The Friends plugin for WordPress is vulnerable...
The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it...
Medium - CVE-2024-12060 - The WP Media Optimizer (.webp) plugin for...
The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-css-resources’ and 'wpmowebp-js-resources' parameters in all versions...
Medium - CVE-2024-12110 - The Gold Addons for Elementor plugin for...
The Gold Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate() and deactivate() functions in all versions...
Critical - CVE-2024-12155 - The SV100 Companion plugin for WordPress is...
The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the settings_import() function...
Medium - CVE-2024-9705 - The Ultimate Coming Soon & Maintenance plugin...
The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite'...
Medium - CVE-2024-9706 - The Ultimate Coming Soon & Maintenance plugin...
The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite function in...
Medium - CVE-2024-9866 - The Event Tickets with Ticket Scanner plugin...
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to...
Medium - CVE-2024-9872 - The Online Booking & Scheduling Calendar for...
The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Medium - CVE-2024-10681 - The The ARMember – Membership Plugin, Content...
The The ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and...
Medium - CVE-2024-10909 - The The Pojo Forms plugin for WordPress is...
The The Pojo Forms plugin for WordPress is vulnerable to arbitrary shortcode execution via form_preview_shortcode AJAX action in all versions up to, and including, 1.4.7. This is due to the...