Medium - CVE-2024-12206 - The WordPress Header Builder Plugin – Pearl...
The WordPress Header Builder Plugin – Pearl plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing or incorrect nonce...
Medium - CVE-2024-12218 - The Woocommerce check pincode/zipcode for...
The Woocommerce check pincode/zipcode for shipping plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.4. This is due to missing or incorrect...
Medium - CVE-2024-12222 - The Deliver via Shipos for WooCommerce plugin...
The Deliver via Shipos for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘dvsfw_bulk_label_url’ parameter in all versions up to, and including, 2.1.7 due...
Medium - CVE-2024-12249 - The GS Insever Portfolio plugin for WordPress...
The GS Insever Portfolio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_settings() function in all versions up to, and...
Medium - CVE-2024-12285 - The SEMA API plugin for WordPress is vulnerable...
The SEMA API plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘catid’ parameter in all versions up to, and including, 5.27 due to insufficient input sanitization and...
High - CVE-2024-12330 - The WP Database Backup – Unlimited Database &...
The WP Database Backup – Unlimited Database & Files Backup by Backup for WP plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.3 via...
Medium - CVE-2024-12394 - The Action Network plugin for WordPress is...
The Action Network plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.4. This is due to missing or incorrect nonce validation on a function....
Medium - CVE-2024-12491 - The SimplyRETS Real Estate IDX plugin for...
The SimplyRETS Real Estate IDX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sr_search_form' shortcode in all versions up to, and including,...
Medium - CVE-2024-12493 - The Files Download Delay plugin for WordPress...
The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' shortcode in all versions up to, and including, 1.0.9 due to...
Medium - CVE-2024-12496 - The Linear plugin for WordPress is vulnerable...
The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissions' shortcode in all versions up to, and including, 2.7.12...