Medium - CVE-2024-12167 - The Shortcodes Blocks Creator Ultimate plugin...
The Shortcodes Blocks Creator Ultimate plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the '_wpnonce' parameter in all versions up to, and including, 2.2.0 due to...
Medium - CVE-2024-12257 - The CardGate Payments for WooCommerce plugin...
The CardGate Payments for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.2.1 due to...
Medium - CVE-2024-7894 - The If Menu plugin for WordPress is vulnerable...
The If Menu plugin for WordPress is vulnerable to unauthorized modification of the plugin's license key due to a missing capability check on the 'actions' function in versions up to,...
Medium - CVE-2024-8679 - The Library Management System – Manage...
The Library Management System – Manage e-Digital Books Library plugin for WordPress is vulnerable to SQL Injection via the ‘value' parameter of the owt_lib_handler AJAX action in all versions...
NA - CVE-2024-11183 - The Simple Side Tab WordPress plugin before...
The Simple Side Tab WordPress plugin before 2.2.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2024-53143 - In the Linux kernel, the following...
In the Linux kernel, the following vulnerability has been resolved: fsnotify: Fix ordering of iput() and watched_objects decrement Ensure the superblock is kept alive until we're done with...
High - CVE-2024-11010 - The FileOrganizer – Manage WordPress and...
The FileOrganizer – Manage WordPress and Website Files plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.1.4 via the 'default_lang'...
Medium - CVE-2024-11367 - The Smoove connector for Elementor forms plugin...
The Smoove connector for Elementor forms plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions...
Medium - CVE-2024-11374 - The TWChat – Send or receive messages from...
The TWChat – Send or receive messages from users plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in...
Medium - CVE-2024-12128 - The Simple Ecommerce Shopping Cart Plugin- Sell...
The Simple Ecommerce Shopping Cart Plugin- Sell products through Paypal plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘monthly_sales_current_year’ parameter in all...