Medium - CVE-2024-10038 - The WP-Strava plugin for WordPress is...
The WP-Strava plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.12.1 due to insufficient input sanitization and output...
Medium - CVE-2024-10577 - The ????(Fat Rat Collect) ????????????????,...
The ????(Fat Rat Collect) ????????????????, ??????????????????????????? plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to missing escaping on a URL in all versions up to,...
High - CVE-2024-10629 - The GPX Viewer plugin for WordPress is...
The GPX Viewer plugin for WordPress is vulnerable to arbitrary file creation due to a missing capability check and file type validation in the gpxv_file_upload() function in all versions up to, and...
Medium - CVE-2024-10686 - The Design for Contact Form 7 Style WordPress...
The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'style_scheme' parameter in all versions...
Medium - CVE-2024-10717 - The Styler for Ninja Forms plugin for WordPress...
The Styler for Ninja Forms plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on the deactivate_license...
Medium - CVE-2024-10778 - The BuddyPress Builder for Elementor –...
The BuddyPress Builder for Elementor – BuddyBuilder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.4 via the 'elementor-template'...
Medium - CVE-2024-10850 - The Razorpay Payment Button Elementor Plugin...
The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on...
Medium - CVE-2024-10851 - The Razorpay Payment Button Plugin plugin for...
The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in...
Medium - CVE-2024-10852 - The Buy one click WooCommerce plugin for...
The Buy one click WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the buy_one_click_export_options AJAX action in all versions up...