Medium - CVE-2024-13749 - The StaffList plugin for WordPress is...
The StaffList plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.2.3. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2025-0808 - The Houzez Property Feed plugin for WordPress...
The Houzez Property Feed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.4.21. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-11746 - The Discover the Best Woocommerce Product...
The Discover the Best Woocommerce Product Brands Plugin for WordPress – Woocommerce Brands Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Medium - CVE-2024-12164 - The WPSyncSheets Lite For WPForms – WPForms...
The WPSyncSheets Lite For WPForms – WPForms Google Spreadsheet Addon plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Critical - CVE-2024-13421 - The Real Estate 7 WordPress theme for WordPress...
The Real Estate 7 WordPress theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.5.1. This is due to the plugin not properly restricting the roles...
High - CVE-2024-13653 - The ZoxPress - The All-In-One WordPress News...
The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on...
High - CVE-2024-13654 - The ZoxPress - The All-In-One WordPress News...
The ZoxPress - The All-In-One WordPress News Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability check on...
High - CVE-2024-13656 - The Click Mag - Viral WordPress News...
The Click Mag - Viral WordPress News Magazine/Blog Theme theme for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing capability...
Medium - CVE-2024-13658 - The NGG Smart Image Search plugin for WordPress...
The NGG Smart Image Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hr_SIS_nextgen_searchbox' shortcode in all versions up to, and...
Medium - CVE-2024-13665 - The Admire Extra plugin for WordPress is...
The Admire Extra plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'space' shortcode in all versions up to, and including, 1.6 due to insufficient...