Medium - CVE-2025-1324 - The WP-Recall – Registration, Profile, Commerce...
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode in all versions up...
Medium - CVE-2025-1325 - The WP-Recall – Registration, Profile, Commerce...
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_preview_post' AJAX...
Medium - CVE-2025-1783 - The Gallery Styles plugin for WordPress is...
The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versions up to, and including, 1.3.4 due to insufficient input sanitization and...
High - CVE-2024-11640 - The VikRentCar Car Rental Management System...
The VikRentCar Car Rental Management System plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorrect nonce...
Medium - CVE-2024-13649 - The 140+ Widgets | Xpro Addons For Elementor –...
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.4.6.7 due to...
Medium - CVE-2024-13675 - The SlingBlocks – Gutenberg Blocks by FunnelKit...
The SlingBlocks – Gutenberg Blocks by FunnelKit (Formerly WooFunnels) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the "Icon List" Block in all versions up to, and...
Medium - CVE-2025-1664 - The Essential Blocks – Page Builder Gutenberg...
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Parallax slider in all versions up to, and...
Medium - CVE-2024-10326 - The RomethemeKit For Elementor plugin for...
The RomethemeKit For Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_options and reset_widgets functions in all...
Medium - CVE-2024-13924 - The Starter Templates by FancyWP plugin for...
The Starter Templates by FancyWP plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 2.0.0 via the...