Medium - CVE-2024-12524 - The Clinked Client Portal plugin for WordPress...
The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-login-button' shortcode in all versions up to, and including,...
NA - CVE-2024-13453 - The The Contact Form & SMTP Plugin for...
The The Contact Form & SMTP Plugin for WordPress by PirateForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.6.0. This is due to the...
NA - CVE-2024-13706 - The WP Image Uploader plugin for WordPress is...
The WP Image Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'file' parameter in all versions up to, and including, 1.0.1 due to insufficient input...
NA - CVE-2025-0739 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to show subscription's information of others users by...
NA - CVE-2025-0740 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain chat messages belonging to other users by changing...
NA - CVE-2025-0741 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to write messages into other users chat by changing the...
NA - CVE-2025-0742 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to obtain files stored by others users by changing the...
NA - CVE-2025-0743 - An Improper Access Control vulnerability has...
An Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker to leverage the endpoint "/embedai/visits/show/" to obtain...
NA - CVE-2025-0744 - an Improper Access Control vulnerability has...
an Improper Access Control vulnerability has been found in EmbedAI 2.1 and below. This vulnerability allows an authenticated attacker change his subscription plan without paying by making a POST...