High - CVE-2024-12542 - The linkID plugin for WordPress is vulnerable...
The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including,...
NA - CVE-2024-12605 - The AI Scribe – SEO AI Writer, Content...
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to Cross-Site Request...
Medium - CVE-2024-12616 - The Bitly's WordPress Plugin plugin for...
The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and...
Medium - CVE-2024-12618 - The Newsletter2Go plugin for WordPress is...
The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'resetStyles' AJAX action in all versions up to, and...
Medium - CVE-2024-12621 - The Yumpu E-Paper publishing plugin for...
The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' shortcode in all versions up to, and including, 3.0.8 due to...
Medium - CVE-2024-12819 - The Searchie plugin for WordPress is vulnerable...
The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortcode in all versions up to, and including, 1.17.0 due to...
High - CVE-2024-12848 - The SKT Page Builder plugin for WordPress is...
The SKT Page Builder plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the 'addLibraryByArchive' function in all versions up to, and...
Medium - CVE-2024-5769 - The MIMO Woocommerce Order Tracking plugin for...
The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and...
Medium - CVE-2024-6155 - The Greenshift – animation and page builder...
The Greenshift – animation and page builder blocks plugin for WordPress is vulnerable to Authenticated (Subscriber+) Server-Side Request Forgery and Stored Cross Site Scripting in all versions up...
NA - CVE-2025-0349 - A vulnerability classified as critical has been...
A vulnerability classified as critical has been found in Tenda AC6 15.03.05.16. Affected is the function GetParentControlInfo of the file /goform/GetParentControlInfo. The manipulation of the...