Medium - CVE-2024-8804 - The Code Embed plugin for WordPress is...
The Code Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's script embed functionality in all versions up to, and including, 2.4 due to insufficient...
Medium - CVE-2024-9242 - The Memberful – Membership Plugin plugin for...
The Memberful – Membership Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'memberful_buy_subscription_link' and...
Medium - CVE-2024-9306 - The WP Booking Calendar plugin for WordPress is...
The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and...
Medium - CVE-2024-9435 - The ShiftController Employee Shift Scheduling...
The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 due to insufficient...
Medium - CVE-2024-9071 - The Easy Demo Importer – A Modern One-Click...
The Easy Demo Importer – A Modern One-Click Demo Import Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.2...
Medium - CVE-2024-9271 - The Re:WP plugin for WordPress is vulnerable to...
The Re:WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.1 due to insufficient input sanitization and output...