|
251851
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Contact Form 7 – Repeatable Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's field_group shortcode in all versions up to, and including, 2.0.1 due to insu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10180
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251852
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Adminify – Custom WordPress Dashboard, Login and Admin Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4…
|
-
|
CVE-2024-8959
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251853
|
- |
|
-
|
-
|
Zohocorp ManageEngine ADAudit Plus versions below 8121 are vulnerable to SQL Injection in the technician reports feature.
|
-
|
CVE-2024-5608
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251854
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in MagePeople Team Event Manager for WooCommerce allows Stored XSS.This issue affects Event M…
|
CWE-79
Cross-site Scripting
|
CVE-2024-49703
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251855
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Woobewoo Product Filter by WBW allows SQL Injection.This issue affects Product Filter by WBW: fro…
|
CWE-89
SQL Injection
|
CVE-2024-49691
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251856
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Schema & Structured Data for WP & AMP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Schema & Structured Data for WP & AMP: …
|
CWE-862
Missing Authorization
|
CVE-2024-49683
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251857
|
- |
|
-
|
-
|
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in smp7, wp.Insider Simple Membership allows Phishing.This issue affects Simple Membership: from n/a through 4.5.3.
|
CWE-601
Open Redirect
|
CVE-2024-49682
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251858
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SWIT WP Sessions Time Monitoring Full Automatic allows SQL Injection.This issue affects WP Sessio…
|
CWE-89
SQL Injection
|
CVE-2024-49681
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251859
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The WP Recipe Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tooltip’ parameter in all versions up to, and including, 9.6.1 due to insufficient input sanitization an…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9650
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251860
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Extra Product Options Builder for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'RednaoSerializedFields' parameter during the creation of a signature file …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9214
|
2024-10-25 21:56 |
2024-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|