Medium - CVE-2024-12072 - The Analytics Cat – Google Analytics Made Easy...
The Analytics Cat – Google Analytics Made Easy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all...
High - CVE-2024-12172 - The WP Courses LMS – Online Courses Builder,...
The WP Courses LMS – Online Courses Builder, eLearning Courses, Courses Solution, Education Courses plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on...
NA - CVE-2024-12255 - The Accept Stripe Payments Using Contact Form 7...
The Accept Stripe Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.5 via the cf7sa-info.php file that returns...
Medium - CVE-2024-12263 - The Child Theme Creator by Orbisius plugin for...
The Child Theme Creator by Orbisius plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the cloud_delete() and cloud_update() functions in...
Medium - CVE-2024-12265 - The Web3 Crypto Payments by DePay for...
The Web3 Crypto Payments by DePay for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/depay/wc/debug REST API...
NA - CVE-2024-9428 - The Popup Builder WordPress plugin before...
The Popup Builder WordPress plugin before 4.3.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2024-9641 - The LuckyWP Table of Contents WordPress plugin...
The LuckyWP Table of Contents WordPress plugin before 2.1.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site...
NA - CVE-2024-9881 - The LearnPress WordPress plugin before 4.2.7.2...
The LearnPress WordPress plugin before 4.2.7.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
Medium - CVE-2024-10583 - The Popup Maker – Boost Sales, Conversions,...
The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘post_title’ parameter...
Medium - CVE-2024-10784 - The Unlimited Elements For Elementor (Free...
The Unlimited Elements For Elementor (Free Widgets, Addons, Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Tile Gallery' widget in all versions up to,...