Medium - CVE-2024-9127 - The Super Testimonials plugin for WordPress is...
The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter in all versions up to, and including, 3.0.0 due to insufficient input...
NA - CVE-2024-9173 - The GF Custom Style plugin for WordPress is...
The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and...
NA - CVE-2024-9198 - Vulnerability in Clibo Manager v1.1.9.1 that...
Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile...
NA - CVE-2024-9199 - Rate limit vulnerability in Clibo Manager...
Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of...
High - CVE-2024-8126 - The Advanced File Manager plugin for WordPress...
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it...
High - CVE-2024-8704 - The Advanced File Manager plugin for WordPress...
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it...
Medium - CVE-2024-8725 - Multiple plugins and/or themes for WordPress...
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css...
NA - CVE-2024-7107 - Files or Directories Accessible to External...
Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.This issue affects CyberMath:...
Medium - CVE-2024-8633 - The Form Maker by 10Web – Mobile-Friendly Drag...
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to...