Medium - CVE-2024-12208 - The Backup and Restore WordPress – Backup...
The Backup and Restore WordPress – Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.50. This is due to missing or incorrect...
Medium - CVE-2024-12214 - The WooCommerce HSS Extension for Streaming...
The WooCommerce HSS Extension for Streaming Video plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘videolink’ parameter in all versions up to, and including, 3.31 due...
Critical - CVE-2024-12252 - The SEO LAT Auto Post plugin for WordPress is...
The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes...
Medium - CVE-2024-12256 - The Simple Video Management System plugin for...
The Simple Video Management System plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'analytics_video' parameter in all versions up to, and including, 1.0.4 due...
Critical - CVE-2024-12264 - The PayU CommercePro Plugin plugin for...
The PayU CommercePro Plugin plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.8.3. This is due to /wp-json/payu/v1/generate-user-token and...
Medium - CVE-2024-12288 - The Simple add pages or posts plugin for...
The Simple add pages or posts plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.0. This is due to missing or incorrect nonce validation....
Medium - CVE-2024-12290 - The Infility Global plugin for WordPress is...
The Infility Global plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘set_type’ parameter in all versions up to, and including, 2.9.8 due to insufficient input...
Medium - CVE-2024-12291 - The ViewMedica 9 plugin for WordPress is...
The ViewMedica 9 plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.15. This is due to missing or incorrect nonce validation on a function....
High - CVE-2024-12313 - The Compare Products for WooCommerce plugin for...
The Compare Products for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.2.1 via deserialization of untrusted input from the...
High - CVE-2024-12322 - The ThePerfectWedding.nl Widget plugin for...
The ThePerfectWedding.nl Widget plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8. This is due to missing or incorrect nonce validation on...