High - CVE-2024-12269 - The Safe Ai Malware Protection for WP plugin...
The Safe Ai Malware Protection for WP plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the export_db() function in all versions up to, and...
Medium - CVE-2024-12299 - The System Dashboard plugin for WordPress is...
The System Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the Filename parameter in all versions up to, and including, 2.8.15 due to insufficient input...
Medium - CVE-2024-12320 - The Team Rosters plugin for WordPress is...
The Team Rosters plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘tab’ parameter in all versions up to, and including, 4.7 due to insufficient input sanitization and...
Medium - CVE-2024-12444 - The WP Dispensary plugin for WordPress is...
The WP Dispensary plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpd_menu' shortcode in all versions up to, and including, 4.5.0 due to...
Medium - CVE-2024-12451 - The HTML5 chat plugin for WordPress is...
The HTML5 chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'HTML5CHAT' shortcode in all versions up to, and including, 1.04 due to insufficient...
High - CVE-2024-12821 - The Media Manager for UserPro plugin for...
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the...
Critical - CVE-2024-12822 - The Media Manager for UserPro plugin for...
The Media Manager for UserPro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the add_capto_img()...
Medium - CVE-2024-12861 - The W2S – Migrate WooCommerce to Shopify plugin...
The W2S – Migrate WooCommerce to Shopify plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.2.1 via the 'viw2s_view_log' AJAX action. This...
Medium - CVE-2024-13349 - The Stockdio Historical Chart plugin for...
The Stockdio Historical Chart plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'stockdio-historical-chart' shortcode in all versions up to, and...
Medium - CVE-2024-13400 - The Kona Gallery Block plugin for WordPress is...
The Kona Gallery Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Kona: Instagram for Gutenberg" Block, specifically in the "align" attribute, in all versions up to,...