Medium - CVE-2024-11786 - The Login with Vipps and MobilePay plugin for...
The Login with Vipps and MobilePay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'continue-with-vipps' shortcode in all versions up to, and...
Medium - CVE-2024-11788 - The StreamWeasels YouTube Integration plugin...
The StreamWeasels YouTube Integration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sw-youtube-embed' shortcode in all versions up to, and...
High - CVE-2024-8066 - The File Manager Pro – Filester plugin for...
The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including,...
High - CVE-2024-9669 - The File Manager Pro – Filester plugin for...
The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. This makes...
Medium - CVE-2024-10670 - The Primary Addon for Elementor plugin for...
The Primary Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.6.2 via the [prim_elementor_template] shortcode due to...
Medium - CVE-2024-10780 - The Restaurant & Cafe Addon for Elementor...
The Restaurant & Cafe Addon for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.5.9 via the 'narestaurant_elementor_template'...
Medium - CVE-2024-10798 - The Royal Elementor Addons and Templates plugin...
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.7.1003 via the 'wpr-template' shortcode due to...
Critical - CVE-2024-11082 - The Tumult Hype Animations plugin for WordPress...
The Tumult Hype Animations plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the hypeanimations_panel() function in all versions up to, and...
Critical - CVE-2024-11103 - The Contest Gallery plugin for WordPress is...
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a...