Medium - CVE-2024-10664 - The Knowledge Base documentation & wiki plugin...
The Knowledge Base documentation & wiki plugin – BasePress Docs plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
High - CVE-2024-11293 - The Registration Forms – User Registration...
The Registration Forms – User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction Social Sites Login plugin for WordPress is vulnerable to...
Medium - CVE-2024-11466 - The Intro Tour Tutorial DeepPresentation plugin...
The Intro Tour Tutorial DeepPresentation plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tab' parameter in all versions up to, and including, 6.5.2 due to...
Medium - CVE-2024-11769 - The Flower Delivery by Florist One plugin for...
The Flower Delivery by Florist One plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'flower-delivery' shortcode in all versions up to, and...
Medium - CVE-2024-11903 - The WP eCards plugin for WordPress is...
The WP eCards plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'ecard' shortcode in all versions up to, and including, 1.3.904 due to insufficient...
High - CVE-2024-10567 - The TI WooCommerce Wishlist plugin for...
The TI WooCommerce Wishlist plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wizard' function in all versions up to, and...
Medium - CVE-2024-10787 - The LA-Studio Element Kit for Elementor plugin...
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' shortcode due...
Medium - CVE-2024-11880 - The B Testimonial – testimonial plugin for WP...
The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'b_testimonial' shortcode in all versions up to, and...
High - CVE-2024-11952 - The Classic Addons – WPBakery Page Builder...
The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all versions up to, and including, 3.0 via the 'style' parameter. This...
Medium - CVE-2024-5020 - Multiple plugins for WordPress are vulnerable...
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to...