NA - CVE-2024-12638 - The Bulk Me Now! WordPress plugin through 2.0...
The Bulk Me Now! WordPress plugin through 2.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...
NA - CVE-2024-12708 - The Bulk Me Now! WordPress plugin through 2.0...
The Bulk Me Now! WordPress plugin through 2.0 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could...
NA - CVE-2024-12709 - The Bulk Me Now! WordPress plugin through 2.0...
The Bulk Me Now! WordPress plugin through 2.0 does not have CSRF checks in some places, which could allow attackers to make logged in users perform unwanted actions via CSRF attacks.
Medium - CVE-2024-12921 - The EthereumICO plugin for WordPress is...
The EthereumICO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ethereum-ico shortcode in all versions up to, and including, 2.4.6 due to insufficient input...
Medium - CVE-2024-13457 - The Event Tickets and Registration plugin for...
The Event Tickets and Registration plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.18.1 via the tc-order-id parameter due to missing...
Medium - CVE-2024-13642 - The Stratum – Elementor Widgets plugin for...
The Stratum – Elementor Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Image Hotspot widget in all versions up to, and including, 1.4.7 due to...
Medium - CVE-2024-13470 - The Ninja Forms – The Contact Form Builder That...
The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode in all versions up to, and...
High - CVE-2024-13694 - The WooCommerce Wishlist (High customization,...
The WooCommerce Wishlist (High customization, fast setup,Free Elementor Wishlist, most features) plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and...
Medium - CVE-2024-13732 - The Responsive Blocks – WordPress Gutenberg...
The Responsive Blocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘section_tag’ parameter in all versions up to, and including, 1.9.9 due...
Medium - CVE-2024-13758 - The CP Contact Form with PayPal plugin for...
The CP Contact Form with PayPal plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.52. This is due to missing or incorrect nonce validation...