Medium - CVE-2024-11915 - The RRAddons for Elementor plugin for WordPress...
The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.0 via the Popup block due to insufficient restrictions on which posts...
Medium - CVE-2024-12116 - The Unlimited Theme Addon For Elementor and...
The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.1 via the 'uta-template'...
Medium - CVE-2024-12407 - The Push Notification for Post and BuddyPress...
The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pushnotificationid' parameter in all versions up to, and...
Medium - CVE-2024-12412 - The Rental and Booking Manager for Bike, Car,...
The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Medium - CVE-2024-12519 - The TCBD Auto Refresher plugin for WordPress is...
The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_refresh' shortcode in all versions up to, and including, 2.0 due...
Medium - CVE-2024-12520 - The Dominion – Domain Checker for WPBakery...
The Dominion – Domain Checker for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dominion_shortcodes_domain_search_6' shortcode in all...
Medium - CVE-2024-12527 - The Perfect Portal Widgets plugin for WordPress...
The Perfect Portal Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'perfect_portal_intake_form' shortcode in all versions up to, and...
Critical - CVE-2024-12877 - The GiveWP – Donation Plugin and Fundraising...
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input...
NA - CVE-2024-42175 - HCL MyXalytics is affected by a weak input...
HCL MyXalytics is affected by a weak input validation vulnerability. The application accepts special characters and there is no length validation. This can lead to security vulnerabilities like...
NA - CVE-2025-0390 - A vulnerability classified as critical was...
A vulnerability classified as critical was found in Guangzhou Huayi Intelligent Technology Jeewms up to 20241229. This vulnerability affects unknown code of the file /wmOmNoticeHController.do. The...