Medium - CVE-2024-10522 - The Co-marquage service-public.fr plugin for...
The Co-marquage service-public.fr plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to,...
Medium - CVE-2024-10528 - The Ultimate Member – User Profile,...
The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized profile picture updates due to...
Medium - CVE-2024-10532 - The Bard Extra plugin for WordPress is...
The Bard Extra plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the bardxtra_import_xml() function in all versions up to, and including,...
Medium - CVE-2024-10623 - The ForumEngine theme for WordPress is...
The ForumEngine theme for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 1.8 due to insufficient input sanitization and output escaping....
Medium - CVE-2024-10671 - The Button Block – Get fully customizable &...
The Button Block – Get fully customizable & multi-functional buttons plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.4 via the [btn_block]...
Medium - CVE-2024-10675 - The affiliate-toolkit plugin for WordPress is...
The affiliate-toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via a URL in all versions up to, and including, 3.6.7 due to insufficient input sanitization and output...
Medium - CVE-2024-10682 - The Announcement & Notification Banner –...
The Announcement & Notification Banner – Bulletin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg and remove_query_arg without appropriate...
Medium - CVE-2024-10726 - The Friendly Functions for Welcart plugin for...
The Friendly Functions for Welcart plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.4. This is due to missing or incorrect nonce validation...
Medium - CVE-2024-10782 - The Theme Builder For Elementor plugin for...
The Theme Builder For Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.2 via the 'elementor-template' shortcode due to...