NA - CVE-2024-4270 - The SVGMagic WordPress plugin through 1.1 does...
The SVGMagic WordPress plugin through 1.1 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
NA - CVE-2024-4271 - The SVGator WordPress plugin through 1.2.6...
The SVGator WordPress plugin through 1.2.6 does not sanitize SVG file contents, which enables users with at least the author role to SVG with malicious JavaScript to conduct Stored XSS attacks.
High - CVE-2024-4404 - The ElementsKit PRO plugin for WordPress is...
The ElementsKit PRO plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 3.6.2 via the 'render_raw' function. This can allow authenticated...
NA - CVE-2024-4480 - The WP Prayer II WordPress plugin through 2.4.7...
The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its email settings, which could allow attackers to make a logged in admin change them via a CSRF attack
NA - CVE-2024-4751 - The WP Prayer II WordPress plugin through 2.4.7...
The WP Prayer II WordPress plugin through 2.4.7 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
NA - CVE-2024-5155 - The Inquiry cart WordPress plugin through 3.4.2...
The Inquiry cart WordPress plugin through 3.4.2 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add...
High - CVE-2024-5551 - The WP STAGING Pro WordPress Backup Plugin...
The WP STAGING Pro WordPress Backup Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.6.0. This is due to missing or incorrect nonce...
High - CVE-2024-31162 - The specific function parameter of ASUS...
The specific function parameter of ASUS Download Master does not properly filter user input. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to...
High - CVE-2024-31163 - ASUS Download Master has a buffer overflow...
ASUS Download Master has a buffer overflow vulnerability. An unauthenticated remote attacker with administrative privileges can exploit this vulnerability to execute arbitrary system commands on...
Medium - CVE-2024-5994 - The WP Go Maps (formerly WP Google Maps) plugin...
The WP Go Maps (formerly WP Google Maps) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom JS option in versions up to, and including, 9.0.38. This makes it possible for...