Critical - CVE-2024-9105 - The UltimateAI plugin for WordPress is...
The UltimateAI plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.8.3. This is due to insufficient verification on the user being supplied in the...
High - CVE-2024-9305 - The AppPresser – Mobile App Framework plugin...
The AppPresser – Mobile App Framework plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 4.4.4. This is due to the...
Medium - CVE-2024-9521 - The SEO Manager plugin for WordPress is...
The SEO Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post meta in versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on...
Critical - CVE-2024-9634 - The GiveWP – Donation Plugin and Fundraising...
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.16.3 via deserialization of untrusted input...
Medium - CVE-2024-9647 - The Kama SpamBlock plugin for WordPress is...
The Kama SpamBlock plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST values in all versions up to, and including, 1.8.2 due to insufficient input sanitization and...
Medium - CVE-2024-9649 - The WP ULike – The Ultimate Engagement Toolkit...
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.4. This is due to missing or...
Medium - CVE-2024-9652 - The Locatoraid Store Locator plugin for...
The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all versions up to, and including, 3.9.47 due to insufficient input sanitization...
Medium - CVE-2024-9891 - The Multiline files upload for contact form 7...
The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the...