Medium - CVE-2024-11874 - The Grid Accordion Lite plugin for WordPress is...
The Grid Accordion Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'grid_accordion' shortcode in all versions up to, and including, 1.5.1 due...
Medium - CVE-2024-11892 - The Accordion Slider Lite plugin for WordPress...
The Accordion Slider Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'accordion_slider' shortcode in all versions up to, and including, 1.5.1...
Medium - CVE-2024-11915 - The RRAddons for Elementor plugin for WordPress...
The RRAddons for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.0 via the Popup block due to insufficient restrictions on which posts...
Medium - CVE-2024-12116 - The Unlimited Theme Addon For Elementor and...
The Unlimited Theme Addon For Elementor and WooCommerce plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.2.1 via the 'uta-template'...
Medium - CVE-2024-12407 - The Push Notification for Post and BuddyPress...
The Push Notification for Post and BuddyPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'pushnotificationid' parameter in all versions up to, and...
Medium - CVE-2024-12412 - The Rental and Booking Manager for Bike, Car,...
The Rental and Booking Manager for Bike, Car, Dress, Resort with WooCommerce Integration – WpRently | WordPress plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Medium - CVE-2024-12519 - The TCBD Auto Refresher plugin for WordPress is...
The TCBD Auto Refresher plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'tcbd_auto_refresh' shortcode in all versions up to, and including, 2.0 due...
Medium - CVE-2024-12520 - The Dominion – Domain Checker for WPBakery...
The Dominion – Domain Checker for WPBakery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dominion_shortcodes_domain_search_6' shortcode in all...
Medium - CVE-2024-12527 - The Perfect Portal Widgets plugin for WordPress...
The Perfect Portal Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'perfect_portal_intake_form' shortcode in all versions up to, and...
Critical - CVE-2024-12877 - The GiveWP – Donation Plugin and Fundraising...
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.19.2 via deserialization of untrusted input...