High - CVE-2024-13890 - The Allow PHP Execute plugin for WordPress is...
The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to allowing PHP code to be entered by all users for whom...
Medium - CVE-2024-13895 - The The Code Snippets CPT plugin for WordPress...
The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is due to the software allowing users to execute an...
Medium - CVE-2025-1481 - The Shortcode Cleaner Lite plugin for WordPress...
The Shortcode Cleaner Lite plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the download_backup() function in all versions up to, and...
Medium - CVE-2025-1504 - The Post Lockdown plugin for WordPress is...
The Post Lockdown plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 4.0.2 via the 'pl_autocomplete' AJAX action due to insufficient...
Medium - CVE-2024-13640 - The Print Invoice & Delivery Notes for...
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.4.1 via the 'wcdn/invoice'...
Medium - CVE-2024-12114 - The FooGallery – Responsive Photo Gallery,...
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,...
Medium - CVE-2024-12119 - The FooGallery – Responsive Photo Gallery,...
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter...
NA - CVE-2024-13825 - The Email Keep WordPress plugin through 1.1...
The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...
NA - CVE-2024-13826 - The Email Keep WordPress plugin through 1.1...
The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Medium - CVE-2024-13844 - The Post SMTP plugin for WordPress is...
The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied...