Medium - CVE-2024-11424 - The Slick Sitemap plugin for WordPress is...
The Slick Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slick-sitemap' shortcode in all versions up to, and including, 2.0.0 due to...
Medium - CVE-2024-11428 - The Lazy load videos and sticky control plugin...
The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lazy-load-videos-and-sticky-control' shortcode in all...
Medium - CVE-2024-11432 - The SuevaFree Essential Kit plugin for...
The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter' shortcode in all versions up to, and including, 1.1.3 due to...
Medium - CVE-2024-11435 - The salavat counter Plugin plugin for WordPress...
The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.1 due to insufficient...
Medium - CVE-2024-11438 - The StreamWeasels Online Status Bar plugin for...
The StreamWeasels Online Status Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-status-bar' shortcode in all versions up to, and including,...
Medium - CVE-2024-11440 - The Grey Owl Lightbox plugin for WordPress is...
The Grey Owl Lightbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gol_button' shortcode in all versions up to, and including, 1.6.1 due to...
Medium - CVE-2024-11447 - The Community by PeepSo – Download from...
The Community by PeepSo – Download from PeepSo.com plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘filter’ parameter in all versions up to, and including, 6.4.6.2 due...
Medium - CVE-2024-11455 - The Include Mastodon Feed plugin for WordPress...
The Include Mastodon Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'include-mastodon-feed' shortcode in all versions up to, and including,...
Medium - CVE-2024-11456 - The Run Contests, Raffles, and Giveaways with...
The Run Contests, Raffles, and Giveaways with ContestsWP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL...
NA - CVE-2024-11595 - FiveCo RAP dissector infinite loop in Wireshark...
FiveCo RAP dissector infinite loop in Wireshark 4.4.0 to 4.4.1 and 4.2.0 to 4.2.8 allows denial of service via packet injection or crafted capture file