Medium - CVE-2024-12114 - The FooGallery – Responsive Photo Gallery,...
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,...
Medium - CVE-2024-12119 - The FooGallery – Responsive Photo Gallery,...
The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter...
NA - CVE-2024-13825 - The Email Keep WordPress plugin through 1.1...
The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against...
NA - CVE-2024-13826 - The Email Keep WordPress plugin through 1.1...
The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
Medium - CVE-2024-13844 - The Post SMTP plugin for WordPress is...
The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied...
High - CVE-2024-11087 - The miniOrange Social Login and Register...
The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9....
High - CVE-2024-13908 - The SMTP by BestWebSoft plugin for WordPress is...
The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions up to, and...
Medium - CVE-2024-10321 - The All-in-One Addons for Elementor – WidgetKit...
The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.4 in...
Medium - CVE-2024-13816 - The Aiomatic - Automatic AI Content Writer &...
The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and loss of data due to a...
High - CVE-2024-13882 - The Aiomatic - Automatic AI Content Writer &...
The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in...