901
|
8.8 |
HIGH
Network
|
wpml
|
wpml
|
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via the Twig Server-Side Template Injection. This is due to missing input validation …
|
CWE-94
Code Injection
|
CVE-2024-6386
|
2024-09-27 22:25 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
902
|
8.8 |
HIGH
Network
|
acymailing
|
acymailing
|
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2024-7384
|
2024-09-27 22:15 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
903
|
6.6 |
MEDIUM
Local
|
linux fedoraproject redhat
|
linux_kernel fedora enterprise_linux
|
A flaw was found in the Netfilter subsystem in the Linux kernel. The issue is in the nft_byteorder_eval() function, where the code iterates through a loop and writes to the `dst` array. On each itera…
|
NVD-CWE-Other
|
CVE-2024-0607
|
2024-09-27 22:15 |
2024-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
904
|
8.8 |
HIGH
Network
|
wpmarketingrobot
|
woocommerce_google_feed_manager
|
The WooCommerce Google Feed Manager plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'wppfm_removeFeedFile' function in all versions up to, and…
|
CWE-862
Missing Authorization
|
CVE-2024-7258
|
2024-09-27 22:05 |
2024-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
905
|
4.3 |
MEDIUM
Network
|
webba-booking
|
webba_booking
|
The Appointment & Event Booking Calendar Plugin – Webba Booking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the save_appearance() func…
|
CWE-862
Missing Authorization
|
CVE-2024-8432
|
2024-09-27 21:58 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
906
|
6.1 |
MEDIUM
Network
|
fatcatapps
|
pixel_cat
|
The Pixel Cat – Conversion Pixel Manager plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions u…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8544
|
2024-09-27 21:57 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
907
|
5.4 |
MEDIUM
Network
|
ggnome
|
garden_gnome_package
|
The Garden Gnome Package plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's ggpkg shortcode in all versions up to, and including, 2.2.9 due to insufficient input sanit…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8657
|
2024-09-27 21:56 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
908
|
6.1 |
MEDIUM
Network
|
ibericode
|
koko_analytics
|
The Koko Analytics plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1…
|
CWE-79
Cross-site Scripting
|
CVE-2024-8662
|
2024-09-27 21:54 |
2024-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
909
|
4.3 |
MEDIUM
Network
|
themify
|
themify_builder
|
The Themify Builder plugin for WordPress is vulnerable to unauthorized post duplication due to missing checks on the duplicate_page_ajaxify function in all versions up to, and including, 7.6.1. This …
|
CWE-863
Incorrect Authorization
|
CVE-2024-7836
|
2024-09-27 21:53 |
2024-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
910
|
7.2 |
HIGH
Network
|
presstigers
|
simple_job_board
|
The Simple Job Board plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.3 via deserialization of untrusted input when editing job applications. This…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-7351
|
2024-09-27 21:48 |
2024-08-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|