Medium - CVE-2024-7721 - The HTML5 Video Player – mp4 Video Player...
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password'...
NA - CVE-2024-7727 - The HTML5 Video Player – mp4 Video Player...
The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the...
NA - CVE-2024-3899 - The Gallery Plugin for WordPress WordPress...
The Gallery Plugin for WordPress WordPress plugin before 1.8.15 does not sanitise and escape some of its image settings, which could allow users with post-writing privilege such as Author to...
NA - CVE-2024-7716 - The Logo Slider WordPress plugin before 3.6.9...
The Logo Slider WordPress plugin before 3.6.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks...
Medium - CVE-2024-8440 - The Essential Addons for Elementor – Best...
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Fancy...
High - CVE-2024-7626 - The WP Delicious – Recipe Plugin for Food...
The WP Delicious – Recipe Plugin for Food Bloggers (formerly Delicious Recipes) plugin for WordPress is vulnerable to arbitrary file movement and reading due to insufficient file path validation in...
Medium - CVE-2024-8045 - The Advanced WordPress Backgrounds plugin for...
The Advanced WordPress Backgrounds plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘imageTag’ parameter in all versions up to, and including, 1.12.3 due to insufficient...
Critical - CVE-2019-25212 - The video carousel slider with lightbox plugin...
The video carousel slider with lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.6 due to insufficient escaping...
Critical - CVE-2024-8277 - The WooCommerce Photo Reviews Premium plugin...
The WooCommerce Photo Reviews Premium plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 1.3.13.2. This is due to the plugin not properly validating...
NA - CVE-2024-45327 - An improper authorization vulnerability...
An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7.0.3 change password endpoint may allow an...