Medium - CVE-2024-7489 - The Forms for Mailchimp by Optin Cat – Grow...
The Forms for Mailchimp by Optin Cat – Grow Your MailChimp List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form color parameters in all versions up to, and including,...
Medium - CVE-2024-9187 - The Read more By Adam plugin for WordPress is...
The Read more By Adam plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the deleteRm() function in all versions up to, and including, 1.1.8. This...
Medium - CVE-2024-9656 - The Mynx Page Builder plugin for WordPress is...
The Mynx Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 0.27.8 due to insufficient input sanitization and...
Medium - CVE-2024-9670 - The 2D Tag Cloud plugin for WordPress is...
The 2D Tag Cloud plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including,...
Medium - CVE-2024-9776 - The ImagePress – Image Gallery plugin for...
The ImagePress – Image Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 1.2.2 due to insufficient input...
NA - CVE-2024-9778 - The ImagePress – Image Gallery plugin for...
The ImagePress – Image Gallery plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.2. This is due to missing or incorrect nonce validation on...
Medium - CVE-2024-9824 - The ImagePress – Image Gallery plugin for...
The ImagePress – Image Gallery plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the 'ip_delete_post' and...
Critical - CVE-2024-9047 - The WordPress File Upload plugin for WordPress...
The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated...
Medium - CVE-2024-9704 - The Social Sharing (by Danny) plugin for...
The Social Sharing (by Danny) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dvk_social_sharing' shortcode in all versions up to, and including,...
Medium - CVE-2024-9756 - The Order Attachments for WooCommerce plugin...
The Order Attachments for WooCommerce plugin for WordPress is vulnerable to unauthorized limited arbitrary file uploads due to a missing capability check on the wcoa_add_attachment AJAX action in...