Medium - CVE-2024-12324 - The Unilevel MLM Plan plugin for WordPress is...
The Unilevel MLM Plan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page’ parameter in all versions up to, and including, 1.1.0 due to insufficient input...
Medium - CVE-2024-12327 - The LazyLoad Background Images plugin for...
The LazyLoad Background Images plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pblzbg_save_settings() function in all versions up...
Medium - CVE-2024-12332 - The School Management System – WPSchoolPress...
The School Management System – WPSchoolPress plugin for WordPress is vulnerable to SQL Injection via the 'cid' parameter in all versions up to, and including, 2.2.14 due to insufficient...
Medium - CVE-2024-12435 - The Compare Products for WooCommerce plugin for...
The Compare Products for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘s_feature’ parameter in all versions up to, and including, 3.2.1 due to...
Medium - CVE-2024-12445 - The RightMessage WP plugin for WordPress is...
The RightMessage WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'rm_area' shortcode in all versions up to, and including, 0.9.7 due to...
Medium - CVE-2024-12453 - The Uptodown APK Download Widget plugin for...
The Uptodown APK Download Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'utd-widget' shortcode in all versions up to, and including, 0.1.2...
Medium - CVE-2024-12457 - The Chat Support for Viber – Chat Bubble and...
The Chat Support for Viber – Chat Bubble and Chat Button for Gutenberg, Elementor and Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Medium - CVE-2024-12462 - The YOGO Booking plugin for WordPress is...
The YOGO Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'yogo-calendar' shortcode in all versions up to, and including, 1.6.2 due to...
Critical - CVE-2024-12470 - The School Management System – SakolaWP plugin...
The School Management System – SakolaWP plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.0.8. This is due to the registration function not properly...
Medium - CVE-2024-9208 - The Enable Accessibility plugin for WordPress...
The Enable Accessibility plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all...