Medium - CVE-2024-8804 - The Code Embed plugin for WordPress is...
The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient...
Medium - CVE-2024-9242 - The Memberful – Membership Plugin plugin for...
The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and...
Medium - CVE-2024-9306 - The WP Booking Calendar plugin for WordPress is...
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and...
Medium - CVE-2024-9435 - The ShiftController Employee Shift Scheduling...
The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 due to insufficient...
Medium - CVE-2024-9071 - The Easy Demo Importer – A Modern One-Click...
The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2...
Medium - CVE-2024-9271 - The Re:WP plugin for WordPress is vulnerable to...
The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output...
NA - CVE-2024-47651 - This vulnerability exists in Shilpi Client...
This vulnerability exists in Shilpi Client Dashboard due to improper handling of multiple parameters in the API endpoint. An authenticated remote attacker could exploit this vulnerability by...
NA - CVE-2024-6400 - Cleartext Storage of Sensitive Information...
Cleartext Storage of Sensitive Information vulnerability in Finrota Netahsilat allows Retrieve Embedded Sensitive Data.This issue solved in versions 1.21.10, 1.23.01, 1.23.08, 1.23.11 and 1.24.03.
NA - CVE-2024-47652 - This vulnerability exists in Shilpi Client...
This vulnerability exists in Shilpi Client Dashboard due to implementation of inadequate authentication mechanism in the login module wherein access to any users account is granted with just their...