Medium - CVE-2024-11091 - The Support SVG – Upload svg files in wordpress...
The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including,...
Medium - CVE-2024-11119 - The BNE Gallery Extended plugin for WordPress...
The BNE Gallery Extended plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'gallery' shortcode in all versions up to, and including, 1.2.1 due to...
Medium - CVE-2024-11192 - The Spotify Play Button for WordPress plugin...
The Spotify Play Button for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's spotifyplaybutton shortcode in all versions up to, and including, 2.11...
Medium - CVE-2024-9170 - The Booster for WooCommerce plugin for...
The Booster for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wcj_product_meta shortcode in all versions up to, and including, 7.2.3 due to...
Medium - CVE-2024-11032 - The Parsi Date plugin for WordPress is...
The Parsi Date plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including,...
NA - CVE-2024-11680 - ProjectSend versions prior to r1720 are...
ProjectSend versions prior to r1720 are affected by an improper authentication vulnerability. Remote, unauthenticated attackers can exploit this flaw by sending crafted HTTP requests to...