|
307851
|
5.3 |
MEDIUM
Network
|
revolut
|
revolut_gateway_for_woocommerce
|
The Revolut Gateway for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the /wc/v3/revolut REST API endpoint in all versions u…
|
CWE-862
Missing Authorization
|
CVE-2024-8678
|
2024-10-3 04:06 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307852
|
5.4 |
MEDIUM
Network
|
wpmet
|
elementskit_elementor_addons
|
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8546
|
2024-10-3 03:56 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307853
|
5.3 |
MEDIUM
Network
|
mycred
|
mycred
|
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress…
|
CWE-862
Missing Authorization
|
CVE-2024-8658
|
2024-10-3 03:36 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307854
|
6.1 |
MEDIUM
Network
|
ninjaforms
|
ninja_forms
|
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient …
|
CWE-79
Cross-site Scripting
|
CVE-2024-3866
|
2024-10-3 03:26 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307855
|
8.8 |
HIGH
Network
|
wclovers
|
frontend_manager_for_woocommerce_along_with_bookings_subscription_listings_compatible
|
The WCFM – Frontend Manager for WooCommerce along with Bookings Subscription Listings Compatible plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and incl…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2024-8290
|
2024-10-3 03:23 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307856
|
5.4 |
MEDIUM
Network
|
braginteractive
|
material_design_icons
|
The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon shortcode in all versions up to, and including, 0.0.5 due to insufficient input s…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9024
|
2024-10-3 03:02 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307857
|
4.8 |
MEDIUM
Network
|
technowich
|
wp_ulike
|
The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even…
|
CWE-79
Cross-site Scripting
|
CVE-2024-7878
|
2024-10-3 02:41 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307858
|
6.4 |
MEDIUM
Local
|
amd
|
epyc_8024pn_firmware epyc_8024p_firmware epyc_8124pn_firmware epyc_8124p_firmware epyc_8224pn_firmware epyc_8224p_firmware epyc_8324pn_firmware epyc_8324p_firmware epyc_8434pn…
|
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and access to the
BIOS menu or UEFI shell to modify the communications buffer potentially
resulting in arbitrar…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2023-20578
|
2024-10-3 02:35 |
2024-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307859
|
4.3 |
MEDIUM
Network
|
wpplugin
|
easy_paypal_events
|
The Easy PayPal Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.1. This is due to missing or incorrect nonce validation on the wpeeve…
|
CWE-352
Origin Validation Error
|
CVE-2024-8476
|
2024-10-3 02:31 |
2024-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307860
|
8.8 |
HIGH
Network
|
supsystic
|
slider social_share_buttons
|
Missing Authorization vulnerability in Supsystic Slider by Supsystic, Supsystic Social Share Buttons by Supsystic.This issue affects Slider by Supsystic: from n/a through 1.8.6; Social Share Buttons …
|
CWE-862
Missing Authorization
|
CVE-2024-47330
|
2024-10-3 02:26 |
2024-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|