NA - CVE-2024-3498 - Attackers can then execute malicious files by...
Attackers can then execute malicious files by enabling certain services of the printer via the web configuration page and elevate its privileges to root. As for the affected...
Critical - CVE-2024-4936 - The Canto plugin for WordPress is vulnerable to...
The Canto plugin for WordPress is vulnerable to Remote File Inclusion in all versions up to, and including, 3.0.8 via the abspath parameter. This makes it possible for unauthenticated attackers to...
NA - CVE-2023-51497 - Missing Authorization vulnerability in Woo...
Missing Authorization vulnerability in Woo WooCommerce Ship to Multiple Addresses.This issue affects WooCommerce Ship to Multiple Addresses: from n/a through 3.8.9.
NA - CVE-2024-1295 - The events-calendar-pro WordPress plugin before...
The events-calendar-pro WordPress plugin before 6.4.0.1, The Events Calendar WordPress plugin before 6.4.0.1 does not prevent users with at least the contributor role from leaking details about...
Medium - CVE-2024-2122 - The Best WordPress Gallery Plugin – FooGallery...
The Best WordPress Gallery Plugin – FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via album gallery custom URLs in all versions up to, and including, 2.4.15 due to...
NA - CVE-2024-2218 - The LuckyWP Table of Contents WordPress plugin...
The LuckyWP Table of Contents WordPress plugin through 2.1.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site...