Medium - CVE-2024-11385 - The Pure CSS Circle Progress bar plugin for...
The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'circle_progress' shortcode in all versions up to, and including,...
Medium - CVE-2024-11388 - The Dino Game – Embed Google Chrome Dinosaur...
The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dino-game' shortcode in all...
High - CVE-2024-11409 - The Grid View Gallery plugin for WordPress is...
The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input from cs_all_photos_details...
Medium - CVE-2024-11412 - The Shine PDF Embeder plugin for WordPress is...
The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shortcode in all versions up to, and including, 1.0 due to...
Medium - CVE-2024-11414 - The RecipePress Reloaded plugin for WordPress...
The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all versions up to, and including, 2.12.0 due to insufficient input sanitization...
Medium - CVE-2024-11416 - The WIP Incoming Lite plugin for WordPress is...
The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-11424 - The Slick Sitemap plugin for WordPress is...
The Slick Sitemap plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slick-sitemap' shortcode in all versions up to, and including, 2.0.0 due to...
Medium - CVE-2024-11428 - The Lazy load videos and sticky control plugin...
The Lazy load videos and sticky control plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lazy-load-videos-and-sticky-control' shortcode in all...
Medium - CVE-2024-11432 - The SuevaFree Essential Kit plugin for...
The SuevaFree Essential Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'counter' shortcode in all versions up to, and including, 1.1.3 due to...
Medium - CVE-2024-11435 - The salavat counter Plugin plugin for WordPress...
The salavat counter Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 0.9.1 due to insufficient...