Medium - CVE-2024-13595 - The Simple Signup Form plugin for WordPress is...
The Simple Signup Form plugin for WordPress is vulnerable to SQL Injection via the 'id' attribute of the 'ssf' shortcode in all versions up to, and including, 1.6.5 due to...
Medium - CVE-2024-13609 - The 1 Click WordPress Migration Plugin – 100%...
The 1 Click WordPress Migration Plugin – 100% FREE for a limited time plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.1 via the...
High - CVE-2024-13622 - The File Uploads Addon for WooCommerce plugin...
The File Uploads Addon for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.7.1 via the 'uploads' directory. This...
High - CVE-2024-13677 - The GetBookingsWP – Appointments Booking...
The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.27....
High - CVE-2024-13684 - The Reset plugin for WordPress is vulnerable to...
The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the reset_db_page()...
Medium - CVE-2024-13687 - The Team Builder – Meet the Team plugin for...
The Team Builder – Meet the Team plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_team_builder_options() function in all...
Critical - CVE-2024-13725 - The Keap Official Opt-in Forms plugin for...
The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possible for...
Medium - CVE-2024-13848 - The Reaction Buttons plugin for WordPress is...
The Reaction Buttons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.1.6 due to insufficient input sanitization and...
High - CVE-2024-13852 - The Option Editor plugin for WordPress is...
The Option Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in version 1.0. This is due to missing nonce validation on the plugin_page() function. This makes it possible for...
Medium - CVE-2025-0796 - The Mortgage Lead Capture System plugin for...
The Mortgage Lead Capture System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.2.10. This is due to missing or incorrect nonce validation...