NA - CVE-2024-7354 - The Ninja Forms WordPress plugin before 3.8.11...
The Ninja Forms WordPress plugin before 3.8.11 does not escape an URL before outputting it back in an attribute, leading to a Reflected Cross-Site Scripting which could be used against high...
NA - CVE-2024-7690 - The DN Popup WordPress plugin through 1.2.2...
The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
NA - CVE-2024-7691 - The Flaming Forms WordPress plugin through...
The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape some parameters, which could allow unauthenticated users to perform Cross-Site Scripting attacks against administrators.
NA - CVE-2024-7692 - The Flaming Forms WordPress plugin through...
The Flaming Forms WordPress plugin through 1.0.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used...
High - CVE-2024-23364 - Transient DOS when processing the...
Transient DOS when processing the non-transmitted BSSID profile sub-elements present within the MBSSID Information Element (IE) of a beacon frame that is received from over-the-air (OTA).