|
308581
|
7.2 |
HIGH
Network
|
wpuserplus
|
userplus
|
The UserPlus plugin for WordPress is vulnerable to unauthorized modification of data due to an improper capability check on the 'save_metabox_form' function in versions up to, and including, 2.0. Thi…
|
NVD-CWE-noinfo
|
CVE-2024-9519
|
2024-10-15 23:26 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308582
|
9.8 |
CRITICAL
Network
|
wpuserplus
|
userplus
|
The UserPlus plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 2.0 due to insufficient restriction on the 'form_actions' and 'userplus_update_user_profile' …
|
NVD-CWE-noinfo
|
CVE-2024-9518
|
2024-10-15 23:25 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308583
|
5.4 |
MEDIUM
Network
|
cssjockey
|
wp_builder
|
The WP Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.0.7 due to insufficient input sanitization and output esc…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9457
|
2024-10-15 23:23 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308584
|
6.1 |
MEDIUM
Network
|
wpfactory
|
products\ _order_\&_customers_export_for_woocommerce
|
The Products, Order & Customers Export for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate esca…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9377
|
2024-10-15 23:18 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308585
|
6.1 |
MEDIUM
Network
|
wpfactory
|
maximum_products_per_user_for_woocommerce
|
The Maximum Products per User for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9205
|
2024-10-15 23:16 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308586
|
5.4 |
MEDIUM
Network
|
secretlab
|
marketing_and_seo_booster
|
The Marketing and SEO Booster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.9.10 due to insufficient input sanitizatio…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9066
|
2024-10-15 23:14 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308587
|
5.4 |
MEDIUM
Network
|
namogo
|
elementor_inline_svg
|
The Elementor Inline SVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.2.0 due to insufficient input sanitization and …
|
CWE-79
Cross-site Scripting
|
CVE-2024-9064
|
2024-10-15 23:11 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308588
|
9.1 |
CRITICAL
Network
|
indutny
|
elliptic
|
The verify function in lib/elliptic/eddsa/index.js in the Elliptic package before 6.5.6 for Node.js omits "sig.S().gte(sig.eddsa.curve.n) || sig.S().isNeg()" validation.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2024-48949
|
2024-10-15 23:07 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308589
|
6.1 |
MEDIUM
Network
|
idiom
|
easy_social_share_buttons
|
The Easy Social Share Buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8729
|
2024-10-15 22:40 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308590
|
4.3 |
MEDIUM
Network
|
brevo
|
newsletter\ _smtp\ _email_marketing_and_subscribe
|
The Newsletter, SMTP, Email marketing and Subscribe forms by Brevo (formely Sendinblue) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.87. …
|
CWE-352
Origin Validation Error
|
CVE-2024-8477
|
2024-10-15 22:30 |
2024-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|