Medium - CVE-2024-11732 - The BP Profile Shortcodes Extra plugin for...
The BP Profile Shortcodes Extra plugin for WordPress is vulnerable to time-based SQL Injection via the ‘tab’ parameter in all versions up to, and including, 2.6.0 due to insufficient escaping on...
Medium - CVE-2024-11805 - The Quick License Manager – WooCommerce Plugin...
The Quick License Manager – WooCommerce Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'submit_qlm_products' parameter in all versions up to, and...
Medium - CVE-2024-11853 - The jAlbum Bridge plugin for WordPress is...
The jAlbum Bridge plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ar’ parameter in all versions up to, and including, 2.0.15 due to insufficient input sanitization and...
Medium - CVE-2024-11898 - The Scratch & Win – Giveaways and Contests....
The Scratch & Win – Giveaways and Contests. Boost subscribers, traffic, repeat visits, referrals, sales and more plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the...
Medium - CVE-2024-11844 - The IdeaPush plugin for WordPress is vulnerable...
The IdeaPush plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the idea_push_taxonomy_save_routine function in all versions up to, and...
Medium - CVE-2024-11866 - The BMLT Tabbed Map plugin for WordPress is...
The BMLT Tabbed Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_tabbed_map' shortcode in all versions up to, and including, 1.1.8 due to...
Medium - CVE-2024-11325 - The AWeber Forms by Optin Cat plugin for...
The AWeber Forms by Optin Cat plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and...
Medium - CVE-2024-11782 - The WP Mailster plugin for WordPress is...
The WP Mailster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'mst_subscribe' shortcode in all versions up to, and including, 1.8.17.0 due to...
Medium - CVE-2024-12062 - The Charity Addon for Elementor plugin for...
The Charity Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.3.2 via the 'nacharity_elementor_template' shortcode due...
NA - CVE-2024-45106 - Improper authentication of an HTTP endpoint in...
Improper authentication of an HTTP endpoint in the S3 Gateway of Apache Ozone 1.4.0 allows any authenticated Kerberos user to revoke and regenerate the S3 secrets of any other user. This is only...