Medium - CVE-2024-11332 - The HIPAA Compliant Forms with Drag’n’Drop...
The HIPAA Compliant Forms with Drag’n’Drop HIPAA Form Builder. Sign HIPAA documents plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'hipaatizer'...
Medium - CVE-2024-11361 - The PDF Invoices & Packing Slips Generator for...
The PDF Invoices & Packing Slips Generator for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the...
Medium - CVE-2024-11387 - The Easy Liveblogs plugin for WordPress is...
The Easy Liveblogs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'elb_liveblog' shortcode in all versions up to, and including, 2.3.5 due to...
Medium - CVE-2024-11408 - The Slotti Ajanvaraus plugin for WordPress is...
The Slotti Ajanvaraus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'slotti' shortcode in all versions up to, and including, 1.3.0 due to...
Medium - CVE-2024-11426 - The AutoListicle: Automatically Update Numbered...
The AutoListicle: Automatically Update Numbered List Articles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'auto-list-number' shortcode in all...
Medium - CVE-2024-11188 - The Formidable Forms – Contact Form Plugin,...
The Formidable Forms – Contact Form Plugin, Survey, Quiz, Payment, Calculator Form & Custom Form Builder plugin for WordPress is vulnerable to POST-Based Reflected Cross-Site Scripting via the...
Medium - CVE-2024-11265 - The Increase Maximum Upload File Size |...
The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.3. This is due to returning...
Medium - CVE-2024-11330 - The Custom CSS, JS & PHP plugin for WordPress...
The Custom CSS, JS & PHP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all...
Medium - CVE-2024-11446 - The Chessgame Shizzle plugin for WordPress is...
The Chessgame Shizzle plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'cs_nonce' parameter in all versions up to, and including, 1.3.0 due to insufficient...
Medium - CVE-2024-9635 - The Checkout with Cash App on WooCommerce...
The Checkout with Cash App on WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wp_http_referer' parameter in several files in all versions up to,...