Medium - CVE-2024-9776 - The ImagePress – Image Gallery plugin for...
The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.2 due to insufficient input...
NA - CVE-2024-9778 - The ImagePress – Image Gallery plugin for...
The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on...
Medium - CVE-2024-9824 - The ImagePress – Image Gallery plugin for...
The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'ip_delete_post' and...
Critical - CVE-2024-9047 - The WordPress File Upload plugin for WordPress...
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated...
Medium - CVE-2024-9704 - The Social Sharing (by Danny) plugin for...
The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including,...
Medium - CVE-2024-9756 - The Order Attachments for WooCommerce plugin...
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in...
Medium - CVE-2024-8760 - The Stackable – Page Builder Gutenberg Blocks...
The Stackable – Page Builder Gutenberg Blocks plugin for WordPress is vulnerable to CSS Injection in all versions up to, and including, 3.13.6. This makes it possible for unauthenticated attackers...
Medium - CVE-2024-8915 - The Category Icon plugin for WordPress is...
The Category Icon plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and...
Medium - CVE-2024-9595 - The TablePress – Tables in WordPress made easy...
The TablePress – Tables in WordPress made easy plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the table cell content in all versions up to, and including, 2.4.2 due to...
Medium - CVE-2024-9696 - The Rescue Shortcodes plugin for WordPress is...
The Rescue Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rescue_tab' shortcode in all versions up to, and including, 2.8 due to...