Medium - CVE-2024-13563 - The Front End Users plugin for WordPress is...
The Front End Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's forgot-password shortcode in all versions up to, and including, 3.2.30 due to...
Medium - CVE-2025-0935 - The Media Library Folders plugin for WordPress...
The Media Library Folders plugin for WordPress is vulnerable to unauthorized plugin settings change due to a missing capability check on several AJAX actions in all versions up to, and including,...
NA - CVE-2025-22208 - A SQL injection vulnerability in the JS Jobs...
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the 'filter_email'...
NA - CVE-2025-22209 - A SQL injection vulnerability in the JS Jobs...
A SQL injection vulnerability in the JS Jobs plugin versions 1.1.5-1.4.3 for Joomla allows authenticated attackers (administrator) to execute arbitrary SQL commands via the...
Critical - CVE-2024-12562 - The s2Member Pro plugin for WordPress is...
The s2Member Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 241216 via deserialization of untrusted input from the...
Medium - CVE-2024-13752 - The WP Project Manager – Task, team, and...
The WP Project Manager – Task, team, and project management plugin featuring kanban board and gantt charts plugin for WordPress is vulnerable to unauthorized loss of data due to a missing...
Medium - CVE-2025-1005 - The ElementsKit Elementor addons plugin for...
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Accordion widget in all versions up to, and including, 3.4.0 due to...
Medium - CVE-2024-10581 - The DirectoryPress Frontend plugin for...
The DirectoryPress Frontend plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.7.9. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-13439 - The Team – Team Members Showcase Plugin plugin...
The Team – Team Members Showcase Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all versions up to, and including,...
High - CVE-2024-13488 - The LTL Freight Quotes – Estes Edition plugin...
The LTL Freight Quotes – Estes Edition plugin for WordPress is vulnerable to SQL Injection via the 'dropship_edit_id' and 'edit_id' parameters in all versions up to, and...