High - CVE-2024-9519 - The UserPlus plugin for WordPress is vulnerable...
The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and...
High - CVE-2024-9522 - The WP Users Masquerade plugin for WordPress is...
The WP Users Masquerade plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 2.0.0. This is due to incorrect authentication and capability checking in the...
High - CVE-2024-9581 - The Shortcodes AnyWhere plugin for WordPress is...
The Shortcodes AnyWhere plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.0.1. This is due to the software allowing users to execute an...
NA - CVE-2024-9685 - The Notification for Telegram plugin for...
The Notification for Telegram plugin for WordPress is vulnerable to unauthorized test message sending due to a missing capability check on the 'nftb_test_action' function in versions up...
Medium - CVE-2024-8477 - The Newsletter, SMTP, Email marketing and...
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
High - CVE-2024-9022 - The TS Poll – Survey, Versus Poll, Image Poll,...
The TS Poll – Survey, Versus Poll, Image Poll, Video Poll plugin for WordPress is vulnerable to SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 2.3.9 due to...
Medium - CVE-2024-9067 - The Youzify – BuddyPress Community, User...
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized modification of data due to a missing...
Medium - CVE-2024-9074 - The Advanced Blocks Pro plugin for WordPress is...
The Advanced Blocks Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.0 due to insufficient input sanitization and...
Medium - CVE-2024-9520 - The UserPlus plugin for WordPress is vulnerable...
The UserPlus plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a missing capability check on multiple functions in all versions up to, and including,...
NA - CVE-2024-9156 - The TI WooCommerce Wishlist WordPress plugin...
The TI WooCommerce Wishlist WordPress plugin through 2.8.2 is vulnerable to SQL Injection due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the...