Medium - CVE-2024-11336 - The Clickbank WordPress Plugin (Storefront)...
The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing or incorrect nonce...
Medium - CVE-2024-11339 - The Smart PopUp Blaster plugin for WordPress is...
The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' shortcode in all versions up to, and including, 1.4.3 due to...
Medium - CVE-2024-11352 - The TwentyTwenty plugin for WordPress is...
The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' shortcode in all versions up to, and including, 1.0.1 due to...
Medium - CVE-2024-11368 - The Splash Sync plugin for WordPress is...
The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including,...
Medium - CVE-2024-11444 - The CLUEVO LMS, E-Learning Platform plugin for...
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce...
Medium - CVE-2024-11450 - The ONLYOFFICE Docs plugin for WordPress is...
The ONLYOFFICE Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice' shortcode in all versions up to, and including, 2.0.0 due to...
Medium - CVE-2024-11687 - The Next-Cart Store to WooCommerce Migration...
The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.9.2 due...
Medium - CVE-2024-11823 - The Folder Gallery plugin for WordPress is...
The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' shortcode in all versions up to, and including, 1.7.4 due to...
Medium - CVE-2024-12003 - The WP System plugin for WordPress is...
The WP System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-12027 - The Message Filter for Contact Form 7 plugin...
The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateFilter() and deleteFilter() functions in...