Medium - CVE-2024-8288 - The Guten Post Layout – An Advanced Post Grid...
The Guten Post Layout – An Advanced Post Grid Collection for WordPress Gutenberg plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘align’ attribute within the...
Medium - CVE-2024-8324 - The XO Slider plugin for WordPress is...
The XO Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘get_slider’ function in all versions up to, and including, 3.8.6 due to insufficient input sanitization and...
Medium - CVE-2024-8430 - The Spice Starter Sites plugin for WordPress is...
The Spice Starter Sites plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the spice_starter_sites_importer_creater function in all...
NA - CVE-2024-8786 - The Auto Featured Image from Title plugin for...
The Auto Featured Image from Title plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up...
Medium - CVE-2024-8793 - The Store Exporter for WooCommerce – Export...
The Store Exporter for WooCommerce – Export Products, Export Orders, Export Subscriptions, and More plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of...
Medium - CVE-2024-8799 - The Custom Banners plugin for WordPress is...
The Custom Banners plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including,...
High - CVE-2024-9018 - The WP Easy Gallery – WordPress Gallery Plugin...
The WP Easy Gallery – WordPress Gallery Plugin plugin for WordPress is vulnerable to time-based SQL Injection via the ‘key’ parameter in all versions up to, and including, 4.8.5 due to insufficient...
Medium - CVE-2024-9209 - The WP Search Analytics plugin for WordPress is...
The WP Search Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and...
Medium - CVE-2024-9220 - The LH Copy Media File plugin for WordPress is...
The LH Copy Media File plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and...
Medium - CVE-2024-9224 - The Hello World plugin for WordPress is...
The Hello World plugin for WordPress is vulnerable to Arbitrary File Reading in all versions up to, and including, 2.1.1 via the hello_world_lyric() function. This makes it possible for...