Medium - CVE-2024-12190 - The Contact Form by Bit Form: Multi Step Form,...
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to unauthorized access of data due to...
High - CVE-2024-12272 - The WP Travel Engine – Elementor Widgets |...
The WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and...
Medium - CVE-2024-12413 - The MarketKing — Ultimate WooCommerce...
The MarketKing — Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to unauthorized access due to missing capability checks on several functions like...
High - CVE-2024-12428 - The WP Data Access – App, Table, Form and Chart...
The WP Data Access – App, Table, Form and Chart Builder plugin plugin for WordPress is vulnerable to SQL Injection via the 'order[user_login][dir]' parameter in all versions up to, and...
Medium - CVE-2024-12636 - The Privacy Policy Generator, Terms &...
The Privacy Policy Generator, Terms & Conditions Generator WordPress Plugin : WP Legal Pages plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including,...
NA - CVE-2024-10858 - The Jetpack WordPress plugin before 14.1 does...
The Jetpack WordPress plugin before 14.1 does not properly checks the postmessage origin in its 13.x versions, allowing it to be bypassed and leading to DOM-XSS. The issue only affects websites...
Medium - CVE-2024-10862 - The NEX-Forms – Ultimate Form Builder – Contact...
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to SQL Injection via the 'search_params' parameter in all versions up to, and...
Critical - CVE-2024-11281 - The WooCommerce Point of Sale plugin for...
The WooCommerce Point of Sale plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 6.1.0. This is due to insufficient validation on the...
Medium - CVE-2024-12335 - The Avada (Fusion) Builder plugin for WordPress...
The Avada (Fusion) Builder plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.11.12 via the handle_clone_post() function and the...