High - CVE-2024-12035 - The CS Framework plugin for WordPress is...
The CS Framework plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the cs_widget_file_delete() function in all versions up to, and including,...
High - CVE-2024-12036 - The CS Framework plugin for WordPress is...
The CS Framework plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 6.9 via the get_widget_settings_json() function. This makes it possible for...
Medium - CVE-2024-12607 - The School Management System for Wordpress...
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'mj_smgt_show_event_task' AJAX action in all...
Medium - CVE-2024-12609 - The School Management System for Wordpress...
The School Management System for Wordpress plugin for WordPress is vulnerable to SQL Injection via the 'view-attendance' page in all versions up to, and including, 92.0.0 due to...
Medium - CVE-2024-12610 - The School Management System for Wordpress...
The School Management System for Wordpress plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'mj_smgt_remove_feetype' and...
Medium - CVE-2024-12611 - The School Management System for Wordpress...
The School Management System for Wordpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'title' parameter in all versions up to, and including, 93.0.0 due...
Critical - CVE-2024-12876 - The Golo - City Travel Guide WordPress Theme...
The Golo - City Travel Guide WordPress Theme theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.6.10. This is due to the plugin...
Medium - CVE-2024-13431 - The Appointment Booking Calendar — Simply...
The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the accent_color and background parameter in...
Medium - CVE-2024-13781 - The Hero Maps Premium plugin for WordPress is...
The Hero Maps Premium plugin for WordPress is vulnerable to SQL Injection via several AJAX actions in all versions up to, and including, 2.3.9 due to insufficient escaping on the user supplied...
Medium - CVE-2024-13904 - The Platform.ly for WooCommerce plugin for...
The Platform.ly for WooCommerce plugin for WordPress is vulnerable to Blind Server-Side Request Forgery in all versions up to, and including, 1.1.6 via the 'hooks' function. This makes it...