Medium - CVE-2024-11759 - The Bukza plugin for WordPress is vulnerable to...
The Bukza plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bukza' shortcode in all versions up to, and including, 2.0.0 due to insufficient input...
Medium - CVE-2024-11763 - The Plezi plugin for WordPress is vulnerable to...
The Plezi plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'plezi' shortcode in all versions up to, and including, 1.0.6 due to insufficient input...
Medium - CVE-2024-11770 - The Post Carousel & Slider plugin for WordPress...
The Post Carousel & Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'post-cs' shortcode in all versions up to, and including, 1.0.4 due to...
Medium - CVE-2024-11855 - The Koalendar – Events & Appointments Booking...
The Koalendar – Events & Appointments Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘height’ parameter in all versions up to, and including, 1.0.2 due...
Medium - CVE-2024-11865 - The Tabs Maker plugin for WordPress is...
The Tabs Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on tab...
Medium - CVE-2024-11867 - The Companion Portfolio – Responsive Portfolio...
The Companion Portfolio – Responsive Portfolio Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'companion-portfolio' shortcode in all...
Medium - CVE-2024-11869 - The Buk for WordPress plugin for WordPress is...
The Buk for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'buk' shortcode in all versions up to, and including, 1.0.7 due to...
Medium - CVE-2024-11873 - The glomex oEmbed plugin for WordPress is...
The glomex oEmbed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glomex_integration' shortcode in all versions up to, and including, 0.9.1 due to...
Medium - CVE-2024-11876 - The Kredeum NFTs, the easiest way to sell your...
The Kredeum NFTs, the easiest way to sell your NFTs directly on your WordPress site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's...
Medium - CVE-2024-11877 - The Cricket Live Score plugin for WordPress is...
The Cricket Live Score plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cricket_score' shortcode in all versions up to, and including, 2.0.2 due to...