|
309151
|
4.3 |
MEDIUM
Network
|
digireturn
|
dn_popup
|
The DN Popup WordPress plugin through 1.2.2 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
|
CWE-352
Origin Validation Error
|
CVE-2024-7690
|
2024-10-8 00:56 |
2024-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309152
|
4.8 |
MEDIUM
Network
|
wow-company
|
viral_signup
|
The Viral Signup WordPress plugin through 2.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks e…
|
CWE-79
Cross-site Scripting
|
CVE-2024-6927
|
2024-10-8 00:56 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309153
|
7.2 |
HIGH
Network
|
stylemixthemes
|
cost_calculator_builder
|
The Cost Calculator Builder WordPress plugin before 3.2.29 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by users with a…
|
CWE-89
SQL Injection
|
CVE-2024-8379
|
2024-10-8 00:49 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309154
|
4.8 |
MEDIUM
Network
|
10web
|
slider
|
The Slider by 10Web WordPress plugin before 1.2.59 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting atta…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8283
|
2024-10-8 00:49 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309155
|
5.4 |
MEDIUM
Network
|
squirrly
|
starbox
|
The Starbox WordPress plugin before 3.5.3 does not properly render social media profiles URLs in certain contexts, like the malicious user's profile or pages where the starbox shortcode is used, whi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8239
|
2024-10-8 00:48 |
2024-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309156
|
4.8 |
MEDIUM
Network
|
ngothang
|
wp_multitasking
|
The WP MultiTasking – WP Utilities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wpmt_menu_name’ parameter in all versions up to, and including, 0.1.17 due to insufficien…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8189
|
2024-10-8 00:44 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309157
|
4.8 |
MEDIUM
Network
|
godaddy
|
coblocks
|
The Page Builder Gutenberg Blocks WordPress plugin before 3.1.13 does not escape the content of post embed via one of its block, which could allow users with the capability to publish posts (editor …
|
CWE-79
Cross-site Scripting
|
CVE-2024-7132
|
2024-10-8 00:44 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309158
|
5.4 |
MEDIUM
Network
|
gutentor
|
gutentor
|
The Gutentor WordPress plugin before 3.3.6 does not validate and escape some of its block options before outputting them back in a page/post where the block is embed, which could allow users with th…
|
CWE-79
Cross-site Scripting
|
CVE-2024-5417
|
2024-10-8 00:44 |
2024-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309159
|
6.1 |
MEDIUM
Network
|
stape
|
gtm_server_side
|
The GTM Server Side plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, …
|
CWE-79
Cross-site Scripting
|
CVE-2024-8712
|
2024-10-8 00:43 |
2024-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309160
|
6.1 |
MEDIUM
Network
|
fetchdesigns
|
sign-up_sheets
|
The Sign-up Sheets WordPress plugin before 2.2.13 does not escape some generated URLs, as well as the $_SERVER['REQUEST_URI'] parameter before outputting them back in attributes, which could lead to …
|
CWE-79
Cross-site Scripting
|
CVE-2024-6020
|
2024-10-8 00:42 |
2024-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|