NA - CVE-2024-6019 - The Music Request Manager WordPress plugin...
The Music Request Manager WordPress plugin through 1.3 does not sanitise and escape incoming music requests, which could allow unauthenticated users to perform Cross-Site Scripting attacks against...
NA - CVE-2024-6887 - The Giveaways and Contests by RafflePress...
The Giveaways and Contests by RafflePress WordPress plugin before 1.12.16 does not sanitise and escape some of its Giveaways settings, which could allow high privilege users such as editor and...
NA - CVE-2024-7766 - The Adicon Server WordPress plugin through 1.2...
The Adicon Server WordPress plugin through 1.2 does not sanitize and escape a parameter before using it in a SQL statement, allowing admins to perform SQL injection attacks
NA - CVE-2024-7816 - The Gixaw Chat WordPress plugin through 1.0...
The Gixaw Chat WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored...
NA - CVE-2024-7817 - The Misiek Photo Album WordPress plugin through...
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF checks in some places, which could allow attackers to make logged in users delete arbitrary albums via a CSRF attack
NA - CVE-2024-7818 - The Misiek Photo Album WordPress plugin through...
The Misiek Photo Album WordPress plugin through 1.4.3 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin...
NA - CVE-2024-7820 - The ILC Thickbox WordPress plugin through 1.0...
The ILC Thickbox WordPress plugin through 1.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
NA - CVE-2024-7822 - The Quick Code WordPress plugin through 1.0...
The Quick Code WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored...
NA - CVE-2024-7859 - The Visual Sound WordPress plugin through 1.03...
The Visual Sound WordPress plugin through 1.03 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
NA - CVE-2024-7860 - The Simple Headline Rotator WordPress plugin...
The Simple Headline Rotator WordPress plugin through 1.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in...