Medium - CVE-2024-9702 - The Social Rocket – Social Sharing Plugin...
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialrocket-floating' shortcode in all versions up to,...
Medium - CVE-2024-11282 - The Passster – Password Protect Pages and...
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search...
High - CVE-2024-11725 - The SMS Alert Order Notifications – WooCommerce...
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on...
Medium - CVE-2024-11764 - The Solar Wizard Lite plugin for WordPress is...
The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'solar_wizard' shortcode in all versions up to, and including, 1.2.4 due to...
Medium - CVE-2024-12437 - The Marketplace Items plugin for WordPress is...
The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'envato' shortcode in all versions up to, and including, 1.5.5 due to...
Medium - CVE-2024-12495 - The Bootstrap Blocks for WP Editor v2 plugin...
The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gtb-bootstrap/column' block in all versions up to, and including, 2.5.0...
Medium - CVE-2024-12499 - The WP jQuery DataTable plugin for WordPress is...
The WP jQuery DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wp_jdt' shortcode in all versions up to, and including, 4.0.1 due to...
Medium - CVE-2024-12624 - The Sina Extension for Elementor plugin for...
The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Sina Image Differ widget in all versions up to, and including, 3.5.91 due to...
Medium - CVE-2024-12781 - The Aurum - WordPress & WooCommerce Shopping...
The Aurum - WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the...
Medium - CVE-2024-9354 - The Estatik Mortgage Calculator plugin for...
The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'color' parameter in all versions up to, and including, 2.0.11 due to...