NA - CVE-2024-7291 - The JetFormBuilder plugin for WordPress is...
The JetFormBuilder plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.3.4.1. This is due to improper restriction on user meta fields. This makes it...
High - CVE-2024-7031 - The File Manager Pro – Filester plugin for...
The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function...
Critical - CVE-2024-7257 - The YayExtra – WooCommerce Extra Product...
The YayExtra – WooCommerce Extra Product Options plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the handle_upload_file function in all versions...
Medium - CVE-2024-7356 - The Zephyr Project Manager plugin for WordPress...
The Zephyr Project Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘filename’ parameter in all versions up to, and including, 3.3.100 due to insufficient input...
Medium - CVE-2024-6709 - The Sync Post With Other Site plugin for...
The Sync Post With Other Site plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'sps_add_update_post' function in all...
Medium - CVE-2024-6872 - The Build Your Dream Website Fast with 400+...
The Build Your Dream Website Fast with 400+ Starter Templates and Landing Pages, No Coding Needed, One-Click Import for Elementor & Gutenberg Blocks! – TemplateSpare plugin for WordPress is...
NA - CVE-2024-38321 - IBM Business Automation Workflow 22.0.2,...
IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 stores potentially sensitive information in log files under certain situations that could be read by an authenticated user. IBM...
NA - CVE-2024-7436 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, has been found in D-Link DI-8100 16.07. This issue affects the function msp_info_htm of the file msp_info.htm. The manipulation of the argument...
NA - CVE-2024-7437 - A vulnerability, which was classified as...
A vulnerability, which was classified as critical, was found in SimpleMachines SMF 2.1.4. Affected is an unknown function of the file /index.php?action=profile;u=2;area=showalerts;do=remove of the...
NA - CVE-2024-37286 - APM server logs contain document body from a...
APM server logs contain document body from a partially failed bulk index request. For example, in case of unavailable_shards_exception for a specific document, since the ES response line contains...