Medium - CVE-2024-11331 - The ??????? ??????? ??????? ???? ???? plugin...
The ??????? ??????? ??????? ???? ???? plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL...
Medium - CVE-2024-11411 - The Spotlightr plugin for WordPress is...
The Spotlightr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spotlightr-v' shortcode in all versions up to, and including, 0.1.9 due to...
Medium - CVE-2024-11774 - The Outdooractive Embed plugin for WordPress is...
The Outdooractive Embed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'list2go' shortcode in all versions up to, and including, 1.5 due to...
Medium - CVE-2024-11775 - The Particle Background plugin for WordPress is...
The Particle Background plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'particleground' shortcode in all versions up to, and including, 1.0.2 due...
Medium - CVE-2024-11783 - The Financial Calculator plugin for WordPress...
The Financial Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'finance_calculator' shortcode in all versions up to, and including, 2.2.1...
Medium - CVE-2024-11784 - The Sell Tickets Online – TicketSource Ticket...
The Sell Tickets Online – TicketSource Ticket Shop for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ticketshop' shortcode in all...
Medium - CVE-2024-11806 - The PKT1 Centro de envios plugin for WordPress...
The PKT1 Centro de envios plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'success' and 'error' parameters in all versions up to, and including,...
Medium - CVE-2024-11812 - The Wtyczka SeoPilot dla WP plugin for...
The Wtyczka SeoPilot dla WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.3.091. This is due to missing or incorrect nonce validation on...
Medium - CVE-2024-11878 - The Category Post Slider plugin for WordPress...
The Category Post Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'category-post-slider' shortcode in all versions up to, and including, 1.4...
Medium - CVE-2024-11893 - The Spoki – Chat Buttons and WooCommerce...
The Spoki – Chat Buttons and WooCommerce Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spoki_button' shortcode in all versions up...