NA - CVE-2024-5765 - The WpStickyBar WordPress plugin through 2.1.0...
The WpStickyBar WordPress plugin through 2.1.0 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading...
NA - CVE-2024-5807 - The Business Card WordPress plugin through...
The Business Card WordPress plugin through 1.0.0 does not prevent high privilege users like administrators from uploading malicious PHP files, which could allow them to run arbitrary code on...
NA - CVE-2024-5808 - The WP Ajax Contact Form WordPress plugin...
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not have CSRF check in place when deleting emails from the email list, which could allow attackers to make a logged in admin perform...
NA - CVE-2024-5809 - The WP Ajax Contact Form WordPress plugin...
The WP Ajax Contact Form WordPress plugin through 2.2.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be...
NA - CVE-2024-5975 - The CZ Loan Management WordPress plugin through...
The CZ Loan Management WordPress plugin through 1.1 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users,...
NA - CVE-2024-6021 - The Donation Block For PayPal WordPress plugin...
The Donation Block For PayPal WordPress plugin through 2.1.0 does not sanitise and escape form submissions, leading to a stored cross-site scripting vulnerability
NA - CVE-2024-6223 - The Send email only on Reply to My Comment...
The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting...
NA - CVE-2024-6224 - The Send email only on Reply to My Comment...
The Send email only on Reply to My Comment WordPress plugin through 1.0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to...
NA - CVE-2024-6226 - The WpStickyBar WordPress plugin through 2.1.0...
The WpStickyBar WordPress plugin through 2.1.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
NA - CVE-2024-6230 - The ?????? ?????? ?????? WordPress plugin...
The ?????? ?????? ?????? WordPress plugin through 2.9.8 does not have CSRF check in place when resetting its form fields, which could allow attackers to make a logged in admin perform such action...