Medium - CVE-2024-11806 - The PKT1 Centro de envios plugin for WordPress...
The PKT1 Centro de envios plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' and 'error' parameters in all versions up to, and including,...
Medium - CVE-2024-11812 - The Wtyczka SeoPilot dla WP plugin for...
The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.091. This is due to missing or incorrect nonce validation on...
Medium - CVE-2024-11878 - The Category Post Slider plugin for WordPress...
The Category Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'category-post-slider' shortcode in all versions up to, and including, 1.4...
Medium - CVE-2024-11893 - The Spoki – Chat Buttons and WooCommerce...
The Spoki – Chat Buttons and WooCommerce Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spoki_button' shortcode in all versions up...
Medium - CVE-2024-12506 - The NACC WordPress Plugin plugin for WordPress...
The NACC WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nacc' shortcode in all versions up to, and including, 4.1.0 due to...
Medium - CVE-2024-12509 - The Embed Twine plugin for WordPress is...
The Embed Twine plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'embed_twine' shortcode in all versions up to, and including, 0.1.0 due to...
Critical - CVE-2024-12571 - The Store Locator for WordPress with Google...
The Store Locator for WordPress with Google Maps – LotsOfLocales plugin for WordPress is vulnerable to Local File Inclusion in version 3.98.9 via the 'sl_engine' parameter. This makes it...
Medium - CVE-2024-9503 - The Maintenance & Coming Soon Redirect...
The Maintenance & Coming Soon Redirect Animation plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Medium - CVE-2024-9619 - The WP SHAPES plugin for WordPress is...
The WP SHAPES plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and output...
NA - CVE-2024-7726 - There exists an unauthenticated accessible JTAG...
There exists an unauthenticated accessible JTAG port on the Kioxia PM6, PM7 and CM6 devices - On the Kioxia CM6, PM6 and PM7 disk drives it was discovered that the 2 main CPU cores of the SoC can...