Medium - CVE-2024-12493 - The Files Download Delay plugin for WordPress...
The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' shortcode in all versions up to, and including, 1.0.9 due to...
Medium - CVE-2024-12496 - The Linear plugin for WordPress is vulnerable...
The Linear plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'linear_block_buy_commissions' shortcode in all versions up to, and including, 2.7.12...
Medium - CVE-2024-12514 - The 3DVieweronline plugin for WordPress is...
The 3DVieweronline plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's '3Dvo-model' shortcode in all versions up to, and including, 2.2.2 due to...
Medium - CVE-2024-12515 - The Muslim Prayer Time-Salah/Iqamah plugin for...
The Muslim Prayer Time-Salah/Iqamah plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Masjid ID parameter in all versions up to, and including, 1.8.8 due to insufficient...
High - CVE-2024-12542 - The linkID plugin for WordPress is vulnerable...
The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including,...
NA - CVE-2024-12605 - The AI Scribe – SEO AI Writer, Content...
The AI Scribe – SEO AI Writer, Content Generator, Humanizer, Blog Writer, SEO Optimizer, DALLE-3, AI WordPress Plugin ChatGPT (GPT-4o 128K) plugin for WordPress is vulnerable to Cross-Site Request...
Medium - CVE-2024-12616 - The Bitly's WordPress Plugin plugin for...
The Bitly's WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX actions in all versions up to, and...
Medium - CVE-2024-12618 - The Newsletter2Go plugin for WordPress is...
The Newsletter2Go plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'resetStyles' AJAX action in all versions up to, and...
Medium - CVE-2024-12621 - The Yumpu E-Paper publishing plugin for...
The Yumpu E-Paper publishing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'YUMPU' shortcode in all versions up to, and including, 3.0.8 due to...
Medium - CVE-2024-12819 - The Searchie plugin for WordPress is vulnerable...
The Searchie plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sio_embed_media' shortcode in all versions up to, and including, 1.17.0 due to...