High - CVE-2024-12025 - The Collapsing Categories plugin for WordPress...
The Collapsing Categories plugin for WordPress is vulnerable to SQL Injection via the 'taxonomy' parameter of the /wp-json/collapsing-categories/v1/get REST API in all versions up to, and...
Medium - CVE-2024-12061 - The Events Addon for Elementor plugin for...
The Events Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2.3 via the naevents_elementor_template shortcode due to...
Medium - CVE-2024-12250 - The Accept Authorize.NET Payments Using Contact...
The Accept Authorize.NET Payments Using Contact Form 7 plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 2.2 via the cf7adn-info.php file. This makes...
High - CVE-2024-12259 - The CRM WordPress Plugin – RepairBuddy plugin...
The CRM WordPress Plugin – RepairBuddy plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 3.8120. This is due to the plugin not...
High - CVE-2024-12432 - The WPC Shop as a Customer for WooCommerce...
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to account takeover and privilege escalation in all versions up to, and including, 1.2.8. This is due to the...
Medium - CVE-2024-12449 - The Video Share VOD – Turnkey Video Site...
The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_player_html' shortcode in all...
Medium - CVE-2024-12596 - The LifterLMS – WP LMS for eLearning, Online...
The LifterLMS – WP LMS for eLearning, Online Courses, & Quizzes plugin for WordPress is vulnerable to arbitrary post deletion due to a missing capability check on the 'llms_delete_cert'...
Medium - CVE-2024-12698 - An incomplete fix for...
An incomplete fix for ose-olm-catalogd-container was issued for the Rapid Reset Vulnerability (CVE-2023-39325/CVE-2023-44487) where only unauthenticated streams were protected, not streams created...
NA - CVE-2024-56169 - A validation integrity issue was discovered in...
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are supposed to maintain a backup cache of the remote RPKI data. This can be...
NA - CVE-2024-56170 - A validation integrity issue was discovered in...
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is...