Medium - CVE-2024-11292 - The WP Private Content Plus plugin for...
The WP Private Content Plus plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.6.1 via the WordPress core search feature. This makes it...
High - CVE-2024-11323 - The AI Quiz | Quiz Maker plugin for WordPress...
The AI Quiz | Quiz Maker plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the...
Medium - CVE-2024-11336 - The Clickbank WordPress Plugin (Storefront)...
The Clickbank WordPress Plugin (Storefront) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7. This is due to missing or incorrect nonce...
Medium - CVE-2024-11339 - The Smart PopUp Blaster plugin for WordPress is...
The Smart PopUp Blaster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'spb-button' shortcode in all versions up to, and including, 1.4.3 due to...
Medium - CVE-2024-11352 - The TwentyTwenty plugin for WordPress is...
The TwentyTwenty plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'twentytwenty' shortcode in all versions up to, and including, 1.0.1 due to...
Medium - CVE-2024-11368 - The Splash Sync plugin for WordPress is...
The Splash Sync plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including,...
Medium - CVE-2024-11444 - The CLUEVO LMS, E-Learning Platform plugin for...
The CLUEVO LMS, E-Learning Platform plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.13.2. This is due to missing or incorrect nonce...
Medium - CVE-2024-11450 - The ONLYOFFICE Docs plugin for WordPress is...
The ONLYOFFICE Docs plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'onlyoffice' shortcode in all versions up to, and including, 2.0.0 due to...
Medium - CVE-2024-11687 - The Next-Cart Store to WooCommerce Migration...
The Next-Cart Store to WooCommerce Migration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 3.9.2 due...
Medium - CVE-2024-11823 - The Folder Gallery plugin for WordPress is...
The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' shortcode in all versions up to, and including, 1.7.4 due to...