Medium - CVE-2024-12512 - The Ask Me Anything (Anonymously) plugin for...
The Ask Me Anything (Anonymously) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'askmeanythingpeople' shortcode in all versions up to, and...
Medium - CVE-2024-12529 - The brodos.net Onlineshop Plugin plugin for...
The brodos.net Onlineshop Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'BrodosCategory' shortcode in all versions up to, and including,...
Medium - CVE-2024-12816 - The NOTICE BOARD BY TOWKIR plugin for WordPress...
The NOTICE BOARD BY TOWKIR plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'notice-board' shortcode in all versions up to, and including, 3.1 due...
Medium - CVE-2024-12817 - The Etsy Importer plugin for WordPress is...
The Etsy Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'product_link' shortcode in all versions up to, and including, 1.4.2 due to...
Medium - CVE-2024-12826 - The GoHero Store Customizer for WooCommerce...
The GoHero Store Customizer for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wooh_action_settings_save_frontend()...
Medium - CVE-2024-12885 - The Connections Business Directory plugin for...
The Connections Business Directory plugin for WordPress is vulnerable to arbitrary directory deletion due to insufficient file path validation when deleting a connections image directory in all...
Medium - CVE-2024-13368 - The Youzify – BuddyPress Community, User...
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the...
Medium - CVE-2024-13370 - The Youzify – BuddyPress Community, User...
The Youzify – BuddyPress Community, User Profile, Social Network & Membership Plugin for WordPress plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the...
Medium - CVE-2024-13441 - The Bilingual Linker plugin for WordPress is...
The Bilingual Linker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the bl_otherlang_link_1 parameter in all versions up to, and including, 2.4 due to insufficient input...
Medium - CVE-2024-13458 - The WordPress SEO Friendly Accordion FAQ with...
The WordPress SEO Friendly Accordion FAQ with AI assisted content generation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'noticefaq' shortcode...