Medium - CVE-2024-5867 - The Delicate theme for WordPress is vulnerable...
The Delicate theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' parameter within the theme's Button shortcode in all versions up to, and including, 3.5.5...
Medium - CVE-2024-5869 - The Neighborly theme for WordPress is...
The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.4 due to...
Medium - CVE-2024-5870 - The Tweaker5 theme for WordPress is vulnerable...
The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.2 due to...
Medium - CVE-2024-5884 - The Beauty theme for WordPress is vulnerable to...
The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in all versions up to, and including, 1.1.4 due to insufficient input...
Medium - CVE-2024-6544 - The Custom Post Limits plugin for WordPress is...
The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. This is due to the plugin utilizing bootstrap and leaving test files...
High - CVE-2024-7423 - The Stream plugin for WordPress is vulnerable...
The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-8242 - The MStore API – Create Native Android & iOS...
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function...
High - CVE-2024-8269 - The MStore API – Create Native Android & iOS...
The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. This is due to the...
Medium - CVE-2024-8714 - The WordPress Affiliates Plugin — SliceWP...
The WordPress Affiliates Plugin — SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL...
Medium - CVE-2024-8730 - The Exit Notifier plugin for WordPress is...
The Exit Notifier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including,...