High - CVE-2024-9698 - The Crafthemes Demo Import plugin for WordPress...
The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_files' function in all versions up to,...
High - CVE-2024-10646 - The Contact Form Plugin by Fluent Forms for...
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in...
Medium - CVE-2024-10690 - The Shortcodes for Elementor plugin for...
The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.4 via the 'SHORTCODE_ELEMENTOR' shortcode due to...
Medium - CVE-2024-11752 - The Eveeno plugin for WordPress is vulnerable...
The Eveeno plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eveeno' shortcode in all versions up to, and including, 1.7 due to insufficient input...
Medium - CVE-2024-12422 - The Import Eventbrite Events plugin for...
The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient...
Medium - CVE-2024-12459 - The Ganohrs Toggle Shortcode plugin for...
The Ganohrs Toggle Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'toggle' shortcode in all versions up to, and including, 0.2.4 due to...
Medium - CVE-2024-12474 - The GeoDataSource Country Region DropDown...
The GeoDataSource Country Region DropDown plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gds-country-dropdown' shortcode in all versions up to,...
Medium - CVE-2024-12501 - The Simple Locator plugin for WordPress is...
The Simple Locator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.0.3 due to insufficient input...
Medium - CVE-2024-11710 - The WP Job Portal – A Complete Recruitment...
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'fieldfor', 'visibleParent' and...
High - CVE-2024-11711 - The WP Job Portal – A Complete Recruitment...
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to SQL Injection via the 'resumeid' parameter in all versions up to,...