High - CVE-2024-7855 - The WP Hotel Booking plugin for WordPress is...
The WP Hotel Booking plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_review() function in all versions up to, and including, 2.1.2....
NA - CVE-2024-7315 - The Migration, Backup, Staging WordPress...
The Migration, Backup, Staging WordPress plugin before 0.9.106 does not use sufficient randomness in the filename that is created when generating a backup, which could be bruteforced by attackers...
NA - CVE-2024-9333 - Permissions bypass in M-Files Connector for...
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation
Medium - CVE-2024-8254 - The Email Subscribers by Icegram Express –...
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions...
Medium - CVE-2024-8800 - The RabbitLoader – Website Speed Optimization...
The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due...
Medium - CVE-2024-8967 - The PWA — easy way to Progressive Web App...
The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient...
Medium - CVE-2024-9172 - The Demo Importer Plus plugin for WordPress is...
The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input sanitization and...