1391
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Simple Downloads List plugin for WordPress is vulnerable to SQL Injection via the 'category' attribute of the 'neofix_sdl' shortcode in all versions up to, and including, 1.4.2 due to insufficien…
|
CWE-89
SQL Injection
|
CVE-2024-13594
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1392
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Precious Metals Charts and Widgets for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'nfusion-widget' shortcode in all versions up to, and including…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13572
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1393
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The WP Google Street View (with 360° virtual tour) & Google maps + Local SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'wpgsv' shortcode in all versions up to…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13542
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1394
|
7.5 |
HIGH
Network
|
-
|
-
|
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 …
|
CWE-22
Path Traversal
|
CVE-2024-13409
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1395
|
7.5 |
HIGH
Network
|
-
|
-
|
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 …
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2024-13408
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1396
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in several widgets in all ve…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13354
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1397
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the tmpcoder_theme_install…
|
CWE-862
Missing Authorization
|
CVE-2024-13335
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1398
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Simple Gallery with Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c2tw_sgwf' shortcode in all versions up to, and including, 2.0 due to insufficient i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13583
|
2025-01-24 19:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1399
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_map' shortcode in all versions up to, and including, 2.6.1 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12494
|
2025-01-24 19:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1400
|
9.8 |
CRITICAL
Network
-
|
-
|
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attacke…
|
CWE-22
Path Traversal
|
CVE-2024-13545
|
2025-01-24 18:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|