High - CVE-2024-10932 - The Backup Migration plugin for WordPress is...
The Backup Migration plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.6 via deserialization of untrusted input in the...
Medium - CVE-2024-11974 - The Media Library Assistant plugin for...
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘smc_settings_tab', 'unattachfixit-action', and 'woofixit-action’...
Medium - CVE-2024-12047 - The WP Compress – Instant Performance & Speed...
The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘custom_server’ parameter in all versions up to, and...
Medium - CVE-2024-12545 - The Scratch & Win – Giveaways and Contests....
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up...
Medium - CVE-2024-12701 - The WP Smart Import : Import any XML File to...
The WP Smart Import : Import any XML File to WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘ page’ parameter in all versions up to, and including, 1.1.2 due...
NA - CVE-2025-0204 - A vulnerability was found in code-projects...
A vulnerability was found in code-projects Online Shoe Store 1.0. It has been rated as critical. This issue affects some unknown processing of the file /details.php. The manipulation of the...
Medium - CVE-2024-11930 - The Taskbuilder – WordPress Project & Task...
The Taskbuilder – WordPress Project & Task Management plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppm_tasks shortcode in all versions up to, and...
Critical - CVE-2024-12583 - The Dynamics 365 Integration plugin for...
The Dynamics 365 Integration plugin for WordPress is vulnerable to Remote Code Execution and Arbitrary File Read in all versions up to, and including, 1.3.23 via Twig Server-Side Template...
NA - CVE-2025-0205 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in code-projects Online Shoe Store 1.0. Affected is an unknown function of the file /details2.php. The manipulation of the argument id leads to...
Medium - CVE-2024-12221 - The Turnkey bbPress by WeaverTheme plugin for...
The Turnkey bbPress by WeaverTheme plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘_wpnonce’ parameter in all versions up to, and including, 1.6.3 due to insufficient...