NA - CVE-2024-5286 - The wp-affiliate-platform WordPress plugin...
The wp-affiliate-platform WordPress plugin before 6.5.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be...
NA - CVE-2024-5287 - The wp-affiliate-platform WordPress plugin...
The wp-affiliate-platform WordPress plugin before 6.5.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in user change them via a CSRF attack
NA - CVE-2024-5442 - The Photo Gallery, Sliders, Proofing and...
The Photo Gallery, Sliders, Proofing and WordPress plugin before 3.59.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored...
NA - CVE-2024-5450 - The Bug Library WordPress plugin before 2.1.1...
The Bug Library WordPress plugin before 2.1.1 does not check the file type on user-submitted bug reports, allowing an unauthenticated user to upload PHP files
NA - CVE-2024-5472 - The WP QuickLaTeX WordPress plugin before 3.8.7...
The WP QuickLaTeX WordPress plugin before 3.8.7 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2024-5575 - The Ditty WordPress plugin before 3.1.43 does...
The Ditty WordPress plugin before 3.1.43 does not sanitise and escape some of its blocks' settings, which could allow high privilege users such as authors to perform Cross-Site Scripting...
NA - CVE-2024-5627 - The Tournamatch WordPress plugin before 4.6.1...
The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some parameters, which could allow users with a role as low as subscriber to perform Cross-Site Scripting attacks.
NA - CVE-2024-5644 - The Tournamatch WordPress plugin before 4.6.1...
The Tournamatch WordPress plugin before 4.6.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks...
NA - CVE-2024-5713 - The If-So Dynamic Content Personalization...
The If-So Dynamic Content Personalization WordPress plugin before 1.8.0.4 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead...
NA - CVE-2024-5715 - The wp-eMember WordPress plugin before 10.6.7...
The wp-eMember WordPress plugin before 10.6.7 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...