High - CVE-2024-6152 - The Flipbox Builder plugin for WordPress is...
The Flipbox Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.5 via deserialization of untrusted input in the...
High - CVE-2024-6431 - The Media.net Ads Manager plugin for WordPress...
The Media.net Ads Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and missing capability check in the 'sendMail' function in all...
Medium - CVE-2024-6545 - The Admin Trim Interface plugin for WordPress...
The Admin Trim Interface plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.1. This is due to the plugin utilizing bootstrap and leaving test files...
NA - CVE-2024-6546 - The One Click Close Comments plugin for...
The One Click Close Comments plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.7.1. This is due to the plugin utilizing bootstrap and leaving test...
Medium - CVE-2024-6547 - The Add Admin CSS plugin for WordPress is...
The Add Admin CSS plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0.1. This is due to the plugin utilizing bootstrap and leaving test files with...
Medium - CVE-2024-6548 - The Add Admin JavaScript plugin for WordPress...
The Add Admin JavaScript plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.0. This is due to the plugin utilizing bootstrap and leaving test files...
Medium - CVE-2024-6549 - The Admin Post Navigation plugin for WordPress...
The Admin Post Navigation plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1. This is due to the plugin utilizing bootstrap and leaving test files...
Medium - CVE-2024-6566 - The Aramex Shipping WooCommerce plugin for...
The Aramex Shipping WooCommerce plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.21. This is due the plugin not preventing direct access to the...
Medium - CVE-2024-6573 - The Intelligence plugin for WordPress is...
The Intelligence plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.4.0. This is due the plugin not preventing direct access to the...
Medium - CVE-2024-6591 - The Ultimate WordPress Auction Plugin plugin...
The Ultimate WordPress Auction Plugin plugin for WordPress is vulnerable to unauthorized email creation and sending due to a missing capability check on the 'send_auction_email_callback'...