High - CVE-2024-13684 - The Reset plugin for WordPress is vulnerable to...
The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the reset_db_page()...
Medium - CVE-2024-13687 - The Team Builder – Meet the Team plugin for...
The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_team_builder_options() function in all...
Critical - CVE-2024-13725 - The Keap Official Opt-in Forms plugin for...
The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possible for...
Medium - CVE-2024-13848 - The Reaction Buttons plugin for WordPress is...
The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.6 due to insufficient input sanitization and...
High - CVE-2024-13852 - The Option Editor plugin for WordPress is...
The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the plugin_page() function. This makes it possible for...
Medium - CVE-2025-0796 - The Mortgage Lead Capture System plugin for...
The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.10. This is due to missing or incorrect nonce validation...
Medium - CVE-2025-0805 - The Mortgage Calculator / Loan Calculator...
The Mortgage Calculator / Loan Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mlcalc' shortcode in all versions up to, and including,...
High - CVE-2024-13315 - The Shopwarden – Automated WooCommerce...
The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.11. This is due to missing or...
Medium - CVE-2024-13438 - The SpeedSize Image & Video AI-Optimizer plugin...
The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce...
High - CVE-2024-13556 - The Affiliate Links: WordPress Plugin for Link...
The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via...