NA - CVE-2024-11839 - Deserialization of Untrusted Data vulnerability...
Deserialization of Untrusted Data vulnerability in PlexTrac (Runbooks modules) which allows Object Injection and arbitrary file writes.This issue affects PlexTrac: from 1.61.3 before 2.8.1.
Medium - CVE-2024-12581 - The Gutenberg Blocks with AI by Kadence WP –...
The Gutenberg Blocks with AI by Kadence WP – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.2.53...
NA - CVE-2024-55918 - An issue was discovered in the...
An issue was discovered in the Graphics::ColorNames package before 3.2.0 for Perl. There is an ambiguity between modules and filenames that can lead to HTML injection by an attacker who can create...
Medium - CVE-2024-11275 - The WP Timetics- AI-powered Appointment Booking...
The WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the...
Medium - CVE-2024-11754 - The Booking System Trafft plugin for WordPress...
The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'trafftbooking' shortcode in all versions up to, and including, 1.0.6 due...
Medium - CVE-2024-11832 - The Beaver Builder – WordPress Page Builder...
The Beaver Builder – WordPress Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom JavaScript row settings in all versions up to, and including, 2.8.4.4...
Medium - CVE-2024-11910 - The WP Crowdfunding plugin for WordPress is...
The WP Crowdfunding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the wp-crowdfunding/search block in all versions up to, and including, 2.1.12 due to insufficient input...
Medium - CVE-2024-11911 - The WP Crowdfunding plugin for WordPress is...
The WP Crowdfunding plugin for WordPress is vulnerable to unauthorized plugin installation due to a missing capability check on the install_woocommerce_plugin() function action in all versions up...
Medium - CVE-2024-12042 - The MStore API – Create Native Android & iOS...
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the profile picture upload functionality in all versions up to,...
Medium - CVE-2024-12309 - The Rate My Post – Star Rating Plugin by...
The Rate My Post – Star Rating Plugin by FeedbackWP plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.4 via the get_post_status() due...