High - CVE-2024-11816 - The Ultimate WordPress Toolkit – WP Extended...
The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to Remote Code Execution in version 3.0.11. This is due to a missing capability check on the...
High - CVE-2024-11916 - The The Ultimate WordPress Toolkit – WP...
The The Ultimate WordPress Toolkit – WP Extended plugin for WordPress is vulnerable to unauthorized modification and retrieval of data due to a missing capability check on several functions in all...
Medium - CVE-2024-12112 - The Easy Form Builder – WordPress plugin form...
The Easy Form Builder – WordPress plugin form builder: contact form, survey form, payment form, and custom form builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Medium - CVE-2024-12521 - The Slotti Ajanvaraus plugin for WordPress is...
The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti-embed-ga' shortcode in all versions up to, and including, 1.3.1 due...
Medium - CVE-2024-12713 - The SureForms – Drag and Drop Form Builder for...
The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the handle_export_form() function...
NA - CVE-2024-56448 - Vulnerability of improper access control in the...
Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulnerability may affect availability.
NA - CVE-2024-56451 - Integer overflow vulnerability during glTF...
Integer overflow vulnerability during glTF model loading in the 3D engine module Impact: Successful exploitation of this vulnerability may affect availability.