Medium - CVE-2024-9649 - The WP ULike – The Ultimate Engagement Toolkit...
The WP ULike – The Ultimate Engagement Toolkit for Websites plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.7.4. This is due to missing or...
Medium - CVE-2024-9652 - The Locatoraid Store Locator plugin for...
The Locatoraid Store Locator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via $_POST keys in all versions up to, and including, 3.9.47 due to insufficient input sanitization...
Medium - CVE-2024-9891 - The Multiline files upload for contact form 7...
The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the...
Medium - CVE-2024-9546 - The WPIDE – File Manager & Code Editor plugin...
The WPIDE – File Manager & Code Editor plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.4.9. This is due to the plugin utilizing the PHP-Parser...