Medium - CVE-2024-10787 - The LA-Studio Element Kit for Elementor plugin...
The LA-Studio Element Kit for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.4.4 via the 'elementor-template' shortcode due...
Medium - CVE-2024-11880 - The B Testimonial – testimonial plugin for WP...
The B Testimonial – testimonial plugin for WP plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'b_testimonial' shortcode in all versions up to, and...
High - CVE-2024-11952 - The Classic Addons – WPBakery Page Builder...
The Classic Addons – WPBakery Page Builder plugin for WordPress is vulnerable to Limited Local PHP File Inclusion in all versions up to, and including, 3.0 via the 'style' parameter. This...
Medium - CVE-2024-5020 - Multiple plugins for WordPress are vulnerable...
Multiple plugins for WordPress are vulnerable to Stored Cross-Site Scripting via the plugin's bundled FancyBox JavaScript library (versions 1.3.4 to 3.5.7) in various versions due to...
Medium - CVE-2024-11814 - The Additional Custom Order Status for...
The Additional Custom Order Status for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the wfwp_wcos_delete_finished, wfwp_wcos_delete_fallback_finished,...