Medium - CVE-2025-0897 - The Modal Window – create popup modal window...
The Modal Window – create popup modal window plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'iframeBox' shortcode in all versions up to, and...
Medium - CVE-2025-1064 - The Login/Signup Popup ( Inline Form +...
The Login/Signup Popup ( Inline Form + Woocommerce ) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's xoo_el_action shortcode in all versions up to, and...
High - CVE-2024-13476 - The LTL Freight Quotes – GlobalTranz Edition...
The LTL Freight Quotes – GlobalTranz Edition plugin for WordPress is vulnerable to SQL Injection via the 'engtz_wd_save_dropship' AJAX endpoint in all versions up to, and including,...
Medium - CVE-2024-13520 - The Gift Cards (Gift Vouchers and Packages)...
The Gift Cards (Gift Vouchers and Packages) (WooCommerce Supported) plugin for WordPress is vulnerable to unauthorized modification of data|loss of data due to a missing capability check on the...
Medium - CVE-2024-13748 - The Ultimate Classified Listings plugin for...
The Ultimate Classified Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Title parameter in all versions up to, and including, 1.4 due to insufficient input...
High - CVE-2024-13753 - The Ultimate Classified Listings plugin for...
The Ultimate Classified Listings plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due to missing or incorrect nonce validation on...
Critical - CVE-2024-13789 - The ravpage plugin for WordPress is vulnerable...
The ravpage plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.31 via deserialization of untrusted input from the 'paramsv2' parameter....
High - CVE-2024-13792 - The WooCommerce Food - Restaurant Menu & Food...
The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software...
Medium - CVE-2024-13802 - The Bandsintown Events plugin for WordPress is...
The Bandsintown Events plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bandsintown_events' shortcode in all versions up to, and including, 1.3.1...
Medium - CVE-2024-13849 - The Cookie Notice Bar plugin for WordPress is...
The Cookie Notice Bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.3.0 due to insufficient input sanitization and output escaping. This...