NA - CVE-2024-4401 - The Elementor Addon Elements plugin for...
The Elementor Addon Elements plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ and 'eae_slider_animation' parameters in all versions up to, and including,...
Medium - CVE-2024-5024 - The Memberpress plugin for WordPress is...
The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'mepr_screenname' and 'mepr_key' parameter in all versions up to, and including,...
Medium - CVE-2024-5061 - The Enfold - Responsive Multi-Purpose Theme...
The Enfold - Responsive Multi-Purpose Theme theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wrapper_class’ and 'class' parameters in all versions up to, and...
High - CVE-2024-5784 - The Tutor LMS Pro plugin for WordPress is...
The Tutor LMS Pro plugin for WordPress is vulnerable to unauthorized administrative actions execution due to a missing capability checks on multiple functions like treport_quiz_atttempt_delete and...
High - CVE-2024-2694 - The Betheme theme for WordPress is vulnerable...
The Betheme theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 27.5.6 via deserialization of untrusted input of the 'mfn-page-items' post meta...
Medium - CVE-2024-3998 - The Betheme theme for WordPress is vulnerable...
The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scripting via several of the plugin's shortcodes in all versions up to, and including, 27.5.6 due to insufficient input...
Medium - CVE-2024-5879 - The HubSpot – CRM, Email Marketing, Live Chat,...
The HubSpot – CRM, Email Marketing, Live Chat, Forms & Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'url' attribute of the HubSpot Meeting Widget in...
NA - CVE-2024-3673 - The Web Directory Free WordPress plugin before...
The Web Directory Free WordPress plugin before 1.7.3 does not validate a parameter before using it in an include(), which could lead to Local File Inclusion issues.
NA - CVE-2024-34577 - Cross-site scripting vulnerability exists in...
Cross-site scripting vulnerability exists in WRC-X3000GS2-B, WRC-X3000GS2-W, and WRC-X3000GS2A-B due to improper processing of input values in easysetup.cgi. If a user views a malicious web page...