NA - CVE-2024-3754 - The Alemha watermarker WordPress plugin through...
The Alemha watermarker WordPress plugin through 1.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting...
NA - CVE-2024-3965 - The Pray For Me WordPress plugin through 1.0.4...
The Pray For Me WordPress plugin through 1.0.4 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
NA - CVE-2024-3966 - The Pray For Me WordPress plugin through 1.0.4...
The Pray For Me WordPress plugin through 1.0.4 does not sanitise and escape some parameters, which could unauthenticated visitors to perform Cross-Site Scripting attacks that trigger when an admin...
NA - CVE-2024-3971 - The Similarity WordPress plugin through 3.0...
The Similarity WordPress plugin through 3.0 does not have CSRF check in place when resetting its settings, which could allow attackers to make a logged in admin reset them via a CSRF attack
NA - CVE-2024-3972 - The Similarity WordPress plugin through 3.0...
The Similarity WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored...
NA - CVE-2024-3977 - The WordPress Jitsi Shortcode WordPress plugin...
The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site...
NA - CVE-2024-3978 - The WordPress Jitsi Shortcode WordPress plugin...
The WordPress Jitsi Shortcode WordPress plugin through 0.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed,...
NA - CVE-2024-3992 - The Amen WordPress plugin through 3.3.1 does...
The Amen WordPress plugin through 3.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even...
NA - CVE-2024-3993 - The AZAN Plugin WordPress plugin through 0.6...
The AZAN Plugin WordPress plugin through 0.6 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored...
NA - CVE-2024-4005 - The Social Pixel WordPress plugin through 2.1...
The Social Pixel WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks...