Medium - CVE-2024-12522 - The Yay! Forms | Embed Custom Forms, Surveys,...
The Yay! Forms | Embed Custom Forms, Surveys, and Quizzes Easily plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yayforms' shortcode in all...
Medium - CVE-2024-13390 - The ADFO – Custom data in admin dashboard...
The ADFO – Custom data in admin dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'adfo_list' shortcode in all versions up to, and...
Medium - CVE-2024-13405 - The Apptivo Business Site CRM plugin for...
The Apptivo Business Site CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.3. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-13462 - The WP Wiki Tooltip plugin for WordPress is...
The WP Wiki Tooltip plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wiki' shortcode in all versions up to, and including, 2.0.2 due to...
High - CVE-2024-13468 - The Trash Duplicate and 301 Redirect plugin for...
The Trash Duplicate and 301 Redirect plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'duplicates-action-top' action in all...
Medium - CVE-2024-13589 - The YouTube Playlists with Schema plugin for...
The YouTube Playlists with Schema plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yt_grid' shortcode in all versions up to, and including, 2.6.1...
Medium - CVE-2024-13591 - The Team Builder For WPBakery Page...
The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'team-builder-vc' shortcode in...
High - CVE-2024-13592 - The Team Builder For WPBakery Page...
The Team Builder For WPBakery Page Builder(Formerly Visual Composer) plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0 via the...
Medium - CVE-2024-13657 - The Store Locator Widget plugin for WordPress...
The Store Locator Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'storelocatorwidget' shortcode in all versions up to, and including,...
Medium - CVE-2024-13660 - The Responsive Flickr Slideshow plugin for...
The Responsive Flickr Slideshow plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fshow' shortcode in all versions up to, and including, 2.6.1 due...