Medium - CVE-2024-9538 - The ShopLentor plugin for WordPress is...
The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php....
Medium - CVE-2024-9543 - The PowerPress Podcasting plugin by Blubrry...
The PowerPress Podcasting plugin by Blubrry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'skipto' shortcode in all versions up to, and...
Medium - CVE-2024-9586 - The Linkz.ai plugin for WordPress is vulnerable...
The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'check_auth' and 'check_logout' functions in...
Medium - CVE-2024-9587 - The Linkz.ai plugin for WordPress is vulnerable...
The Linkz.ai plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_linkz' function in versions up to, and including,...
Medium - CVE-2024-9610 - The Language Switcher plugin for WordPress is...
The Language Switcher plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and...
Medium - CVE-2024-9611 - The Increase upload file size & Maximum...
The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the...
Medium - CVE-2024-9616 - The BlockMeister – Block Pattern Builder plugin...
The BlockMeister – Block Pattern Builder plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions...
Critical - CVE-2024-9707 - The Hunk Companion plugin for WordPress is...
The Hunk Companion plugin for WordPress is vulnerable to unauthorized plugin installation/activation due to a missing capability check on the /wp-json/hc/v1/themehunk-import REST API endpoint in...
NA - CVE-2024-9855 - A vulnerability was found in 07FLYCMS,...
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been declared as critical. Affected by this vulnerability is the function uploadFile of the file...
NA - CVE-2024-9856 - A vulnerability was found in 07FLYCMS,...
A vulnerability was found in 07FLYCMS, 07FLY-CMS and 07FlyCRM 1.3.8. It has been rated as problematic. Affected by this issue is some unknown functionality of the component System Settings Page....