NA - CVE-2024-9578 - The Hide Links plugin for WordPress is...
The Hide Links plugin for WordPress is vulnerable to unauthorized shortcode execution due to do_shortcode being hooked through the comment_text filter in all versions up to and including 1.4.2....
Medium - CVE-2024-9614 - The Constant Contact Forms by MailMunch plugin...
The Constant Contact Forms by MailMunch plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions...
Medium - CVE-2024-10529 - The Kognetiks Chatbot for WordPress plugin for...
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_assistant() function in all versions up...
Medium - CVE-2024-10530 - The Kognetiks Chatbot for WordPress plugin for...
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the add_new_assistant() function in all versions up...
Medium - CVE-2024-10531 - The Kognetiks Chatbot for WordPress plugin for...
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_assistant() function in all versions up...
Medium - CVE-2024-10593 - The WPForms – Easy Form Builder for WordPress –...
The WPForms – Easy Form Builder for WordPress – Contact Forms, Payment Forms, Surveys, & More plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
Medium - CVE-2024-10684 - The Kognetiks Chatbot for WordPress plugin for...
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 2.1.7 due to...
Medium - CVE-2024-10882 - The Product Delivery Date for WooCommerce –...
The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping...
Medium - CVE-2024-11143 - The Kognetiks Chatbot for WordPress plugin for...
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.8. This is due to missing or incorrect nonce...
High - CVE-2024-10174 - The WP Project Manager – Task, team, and...
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up...