High - CVE-2024-10587 - The Interactive Contact Form and Multi Step...
The Interactive Contact Form and Multi Step Form Builder with Drag & Drop Editor – Funnelforms Free plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including,...
Medium - CVE-2024-10663 - The Eleblog – Elementor Blog And Magazine...
The Eleblog – Elementor Blog And Magazine Addons plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the goodbye_form_callback() function in...
Medium - CVE-2024-10832 - The Posti Shipping plugin for WordPress is...
The Posti Shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.10.3. This is due to missing or incorrect nonce validation on the...
High - CVE-2024-10952 - The The Authors List plugin for WordPress is...
The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution via update_authors_list_ajax AJAX action in all versions up to, and including, 2.0.4. This is due to the...
Medium - CVE-2024-11093 - The SG Helper plugin for WordPress is...
The SG Helper plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.0 due to insufficient input sanitization and output escaping. This makes it...
Medium - CVE-2024-11747 - The Responsive Videos plugin for WordPress is...
The Responsive Videos plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'somryv' shortcode in all versions up to, and including, 2.1 due to...
Medium - CVE-2024-11807 - The NPS computy plugin for WordPress is...
The NPS computy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'data1' and 'data2' parameters in all versions up to, and including, 2.8.0 due to...
Medium - CVE-2024-11813 - The Pulsating Chat Button plugin for WordPress...
The Pulsating Chat Button plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.6. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-11897 - The Contact Form, Survey & Form Builder –...
The Contact Form, Survey & Form Builder – MightyForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mightyforms' shortcode in all versions up...
Medium - CVE-2024-10885 - The SearchIQ – The Search Solution plugin for...
The SearchIQ – The Search Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'siq_searchbox' shortcode in all versions up to, and including,...