Medium - CVE-2024-11881 - The Easy Waveform Player plugin for WordPress...
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'easywaveformplayer' shortcode in all versions up to, and including, 1.2.0...
Medium - CVE-2024-12500 - The Philantro – Donations and Donor Management...
The Philantro – Donations and Donor Management plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes like 'donate' in all versions up to, and...
Medium - CVE-2024-12513 - The Contests by Rewards Fuel plugin for...
The Contests by Rewards Fuel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'RF_CONTEST' shortcode in all versions up to, and including, 2.0.65...
NA - CVE-2024-47480 - Dell Inventory Collector Client, versions prior...
Dell Inventory Collector Client, versions prior to 12.7.0, contains an Improper Link Resolution Before File Access vulnerability. A low-privilege attacker with local access may exploit this...
Medium - CVE-2024-11254 - The AMP for WP – Accelerated Mobile Pages...
The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the disqus_name parameter in all versions up to, and including, 1.1.1 due to...
High - CVE-2024-12025 - The Collapsing Categories plugin for WordPress...
The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and...
Medium - CVE-2024-12061 - The Events Addon for Elementor plugin for...
The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.3 via the naevents_elementor_template shortcode due to...
Medium - CVE-2024-12250 - The Accept Authorize.NET Payments Using Contact...
The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2 via the cf7adn-info.php file. This makes...
High - CVE-2024-12259 - The CRM WordPress Plugin – RepairBuddy plugin...
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not...
High - CVE-2024-12432 - The WPC Shop as a Customer for WooCommerce...
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the...