Medium - CVE-2024-12502 - The My IDX Home Search plugin for WordPress is...
The My IDX Home Search plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'homeasap-idx-landing' shortcode in all versions up to, and including, 2.0.1...
Medium - CVE-2024-12517 - The WooCommerce Cart Count Shortcode plugin for...
The WooCommerce Cart Count Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'cart_button' shortcode in all versions up to, and including,...
Medium - CVE-2024-12523 - The States Map US plugin for WordPress is...
The States Map US plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'states_map' shortcode in all versions up to, and including, 2.4.2 due to...
Medium - CVE-2024-12555 - The SIP Calculator plugin for WordPress is...
The SIP Calculator plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on a function. This makes it...
Medium - CVE-2024-12578 - The Tickera – WordPress Event Ticketing plugin...
The Tickera – WordPress Event Ticketing plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 3.5.4.8 via the 'tickera_tickets_info' endpoint....
High - CVE-2024-9698 - The Crafthemes Demo Import plugin for WordPress...
The Crafthemes Demo Import plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'process_uploaded_files' function in all versions up to,...
High - CVE-2024-10646 - The Contact Form Plugin by Fluent Forms for...
The Contact Form Plugin by Fluent Forms for Quiz, Survey, and Drag & Drop WP Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the form's subject parameter in...
Medium - CVE-2024-10690 - The Shortcodes for Elementor plugin for...
The Shortcodes for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.0.4 via the 'SHORTCODE_ELEMENTOR' shortcode due to...
Medium - CVE-2024-11752 - The Eveeno plugin for WordPress is vulnerable...
The Eveeno plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'eveeno' shortcode in all versions up to, and including, 1.7 due to insufficient input...
Medium - CVE-2024-12422 - The Import Eventbrite Events plugin for...
The Import Eventbrite Events plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 1.7.4 due to insufficient...