Medium - CVE-2024-12453 - The Uptodown APK Download Widget plugin for...
The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd-widget' shortcode in all versions up to, and including, 0.1.2...
Medium - CVE-2024-12457 - The Chat Support for Viber – Chat Bubble and...
The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Medium - CVE-2024-12462 - The YOGO Booking plugin for WordPress is...
The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shortcode in all versions up to, and including, 1.6.2 due to...
Critical - CVE-2024-12470 - The School Management System – SakolaWP plugin...
The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly...
Medium - CVE-2024-9208 - The Enable Accessibility plugin for WordPress...
The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all...
NA - CVE-2024-10102 - The Photo Gallery, Images, Slider in Rbs Image...
The Photo Gallery, Images, Slider in Rbs Image Gallery WordPress plugin before 3.2.22 does not sanitise and escape some of its Gallery settings, which could allow high privilege users such as...
Medium - CVE-2024-10536 - The FancyPost – Best Ultimate Post Block, Post...
The FancyPost – Best Ultimate Post Block, Post Grid, Layouts, Carousel, Slider For Gutenberg & Elementor plugin for WordPress is vulnerable to unauthorized access of data due to a missing...
NA - CVE-2024-10562 - The Form Maker by 10Web WordPress plugin...
The Form Maker by 10Web WordPress plugin before 1.15.31 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site...
Medium - CVE-2024-11369 - The Store credit / Gift cards for woocommerce...
The Store credit / Gift cards for woocommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'coupon', 'start_date', and 'end_date'...
NA - CVE-2024-11606 - The Tabs Shortcode WordPress plugin through...
The Tabs Shortcode WordPress plugin through 2.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could...