Medium - CVE-2024-10636 - The Quiz Maker Business, Developer, and Agency...
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0...
NA - CVE-2025-24858 - Develocity (formerly Gradle Enterprise) before...
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by...
Medium - CVE-2024-10705 - The Multiple Page Generator Plugin – MPG plugin...
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpg_download_file_by_link'...
Medium - CVE-2024-11090 - The Membership Plugin – Restrict Content plugin...
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature....
NA - CVE-2024-46881 - Develocity (formerly Gradle Enterprise) before...
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration...
High - CVE-2024-11641 - The VikBooking Hotel Booking Engine & PMS...
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce...
High - CVE-2024-11936 - The Zox News theme for WordPress is vulnerable...
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and...
Medium - CVE-2024-12334 - The WC Affiliate – A Complete WooCommerce...
The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up to, and including, 2.4 due to...
Medium - CVE-2024-13505 - The Survey Maker plugin for WordPress is...
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to...