Medium - CVE-2024-11823 - The Folder Gallery plugin for WordPress is...
The Folder Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'foldergallery' shortcode in all versions up to, and including, 1.7.4 due to...
Medium - CVE-2024-12003 - The WP System plugin for WordPress is...
The WP System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.1. This is due to missing or incorrect nonce validation on the...
Medium - CVE-2024-12027 - The Message Filter for Contact Form 7 plugin...
The Message Filter for Contact Form 7 plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the updateFilter() and deleteFilter() functions in...
Medium - CVE-2024-12028 - The Friends plugin for WordPress is vulnerable...
The Friends plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several REST API endpoints in all versions up to, and including, 3.2.1. This makes it...
Medium - CVE-2024-12060 - The WP Media Optimizer (.webp) plugin for...
The WP Media Optimizer (.webp) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘wpmowebp-css-resources’ and 'wpmowebp-js-resources' parameters in all versions...
Medium - CVE-2024-12110 - The Gold Addons for Elementor plugin for...
The Gold Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the activate() and deactivate() functions in all versions...
Critical - CVE-2024-12155 - The SV100 Companion plugin for WordPress is...
The SV100 Companion plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the settings_import() function...
Medium - CVE-2024-9705 - The Ultimate Coming Soon & Maintenance plugin...
The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ucsm_update_template_name_lite'...
Medium - CVE-2024-9706 - The Ultimate Coming Soon & Maintenance plugin...
The Ultimate Coming Soon & Maintenance plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ucsm_activate_lite_template_lite function in...
Medium - CVE-2024-9866 - The Event Tickets with Ticket Scanner plugin...
The Event Tickets with Ticket Scanner plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameters in all versions up to, and including, 2.4.4 due to...