Medium - CVE-2024-11360 - The Page Parts plugin for WordPress is...
The Page Parts plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including,...
Medium - CVE-2024-11365 - The Crypto and DeFi Widgets – Web3...
The Crypto and DeFi Widgets – Web3 Cryptocurrency Shortcodes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the...
Medium - CVE-2024-11370 - The Subaccounts for WooCommerce plugin for...
The Subaccounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to,...
Medium - CVE-2024-11371 - The Theater for WordPress plugin for WordPress...
The Theater for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and...
Medium - CVE-2024-11385 - The Pure CSS Circle Progress bar plugin for...
The Pure CSS Circle Progress bar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'circle_progress' shortcode in all versions up to, and including,...
Medium - CVE-2024-11388 - The Dino Game – Embed Google Chrome Dinosaur...
The Dino Game – Embed Google Chrome Dinosaur Game in WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dino-game' shortcode in all...
High - CVE-2024-11409 - The Grid View Gallery plugin for WordPress is...
The Grid View Gallery plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0 via deserialization of untrusted input from cs_all_photos_details...
Medium - CVE-2024-11412 - The Shine PDF Embeder plugin for WordPress is...
The Shine PDF Embeder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shinepdf' shortcode in all versions up to, and including, 1.0 due to...
Medium - CVE-2024-11414 - The RecipePress Reloaded plugin for WordPress...
The RecipePress Reloaded plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Recipe Ingredients in all versions up to, and including, 2.12.0 due to insufficient input sanitization...
Medium - CVE-2024-11416 - The WIP Incoming Lite plugin for WordPress is...
The WIP Incoming Lite plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the...