High - CVE-2024-11036 - The The GamiPress – The #1 gamification plugin...
The The GamiPress – The #1 gamification plugin to reward points, achievements, badges & ranks in WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution via...
High - CVE-2024-11038 - The The WPB Popup for Contact Form 7 – Showing...
The The WPB Popup for Contact Form 7 – Showing The Contact Form 7 Popup on Button Click – CF7 Popup plugin for WordPress is vulnerable to arbitrary shortcode execution via wpb_pcf_fire_contact_form...
NA - CVE-2024-11195 - The Email Subscription Popup plugin for...
The Email Subscription Popup plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's print_email_subscribe_form shortcode in all versions up to, and including,...
High - CVE-2024-11194 - The Classified Listing – Classified ads &...
The Classified Listing – Classified ads & Business Directory Plugin plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a...
Medium - CVE-2024-11198 - The GD Rating System plugin for WordPress is...
The GD Rating System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘extra_class’ parameter in all versions up to, and including, 3.6.1 due to insufficient input...
Medium - CVE-2024-11224 - The Parallax Image plugin for WordPress is...
The Parallax Image plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘position’ parameter in all versions up to, and including, 1.9 due to insufficient input sanitization...
Medium - CVE-2024-9777 - The Ashe theme for WordPress is vulnerable to...
The Ashe theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.243....
NA - CVE-2024-9830 - The Bard theme for WordPress is vulnerable to...
The Bard theme for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.216....
NA - CVE-2024-10204 - Heap-based Buffer Overflow and Uninitialized...
Heap-based Buffer Overflow and Uninitialized Variable vulnerabilities exist in the X_B and SAT file reading procedure in eDrawings from Release SOLIDWORKS 2024 through Release SOLIDWORKS 2025....