Medium - CVE-2024-13367 - The Sandbox plugin for WordPress is vulnerable...
The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_download action in all versions up to, and including, 0.4. This makes it...
Medium - CVE-2024-13386 - The quote-posttype-plugin plugin for WordPress...
The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all versions up to, and including, 1.2.2 due to insufficient input sanitization...
NA - CVE-2024-11139 - CWE-119: Improper Restriction of Operations...
CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could allow local attackers to exploit these issues to potentially execute arbitrary code...
NA - CVE-2024-11425 - CWE-131: Incorrect Calculation of Buffer Size...
CWE-131: Incorrect Calculation of Buffer Size vulnerability exists that could cause Denial-of-Service of the product when an unauthenticated user is sending a crafted HTTPS packet to the webserver.
Medium - CVE-2024-12370 - The WP Hotel Booking plugin for WordPress is...
The WP Hotel Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check when adding rooms in all versions up to, and including, 2.1.5. This...
NA - CVE-2024-12399 - CWE-924: Improper Enforcement of Message...
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause partial loss of confidentiality, loss of integrity and...
NA - CVE-2024-12476 - CWE-611: Improper Restriction of XML External...
CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure, impacts workstation integrity and potential remote code execution on...
High - CVE-2024-13377 - The Gravity Forms plugin for WordPress is...
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alt’ parameter in all versions up to, and including, 2.9.1.3 due to insufficient input sanitization and...
Medium - CVE-2024-13378 - The Gravity Forms plugin for WordPress is...
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style_settings’ parameter in versions 2.9.0.1 up to, and including, 2.9.1.3 due to insufficient input...
NA - CVE-2024-10497 - CWE-639: Authorization Bypass Through...
CWE-639: Authorization Bypass Through User-Controlled Key vulnerability exists that could allow an authorized attacker to modify values outside those defined by their privileges (Elevation of...