NA - CVE-2024-9333 - Permissions bypass in M-Files Connector for...
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation
Medium - CVE-2024-8254 - The Email Subscribers by Icegram Express –...
The Email Subscribers by Icegram Express – Email Marketing, Newsletters, Automation for WordPress & WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions...
Medium - CVE-2024-8800 - The RabbitLoader – Website Speed Optimization...
The RabbitLoader – Website Speed Optimization for improving Core Web Vital metrics with Cache, Image Optimization, and more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due...
Medium - CVE-2024-8967 - The PWA — easy way to Progressive Web App...
The PWA — easy way to Progressive Web App plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.6.3 due to insufficient...
Medium - CVE-2024-9172 - The Demo Importer Plus plugin for WordPress is...
The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input sanitization and...
Medium - CVE-2024-9210 - The MC4WP: Mailchimp Top Bar plugin for...
The MC4WP: Mailchimp Top Bar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and...
Medium - CVE-2024-9222 - The Paid Membership Subscriptions – Effortless...
The Paid Membership Subscriptions – Effortless Memberships, Recurring Payments & Content Restriction plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of...
Medium - CVE-2024-9225 - The SEOPress – On-site SEO plugin for WordPress...
The SEOPress – On-site SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all...
Medium - CVE-2024-9218 - The Magazine Blocks – Blog Designer, Magazine &...
The Magazine Blocks – Blog Designer, Magazine & Newspaper Website Builder, Page Builder with Posts Blocks, Post Grid plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the...