NA - CVE-2024-10103 - In the process of testing the MailPoet...
In the process of testing the MailPoet WordPress plugin before 5.3.2, a vulnerability was found that allows you to implement Stored XSS on behalf of the editor by embedding malicious script, which...
NA - CVE-2024-8403 - Improper Validation of Specified Type of Input...
Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 and later and FX5-ENET/IP versions 1.100 to 1.104 allows a...
Medium - CVE-2024-10268 - The MP3 Audio Player – Music Player, Podcast...
The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all...
High - CVE-2024-10388 - The WordPress GDPR plugin for WordPress is...
The WordPress GDPR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_firstname' and 'gdpr_lastname' parameters in all versions up to, and...
Medium - CVE-2024-11069 - The WordPress GDPR plugin for WordPress is...
The WordPress GDPR plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'WordPress_GDPR_Data_Delete::check_action' function in all...
Medium - CVE-2024-11098 - The SVG Block plugin for WordPress is...
The SVG Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.24 due to insufficient input sanitization and...
NA - CVE-2024-31141 - Files or Directories Accessible to External...
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior,...
High - CVE-2024-11036 - The The GamiPress – The #1 gamification plugin...
The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via...
High - CVE-2024-11038 - The The WPB Popup for Contact Form 7 – Showing...
The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary shortcode execution via wpb_pcf_fire_contact_form...
NA - CVE-2024-11195 - The Email Subscription Popup plugin for...
The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including,...