881
|
- |
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Amento Tech Pvt ltd WPGuppy allows Privilege Escalation.This issue affects WPGuppy: from n/a through 1.1.0.
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2024-56280
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
882
|
- |
|
-
|
-
|
Server-Side Request Forgery (SSRF) vulnerability in Tips and Tricks HQ Compact WP Audio Player allows Server Side Request Forgery.This issue affects Compact WP Audio Player: from n/a through 1.9.14.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-56279
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
883
|
- |
|
-
|
-
|
Improper Control of Generation of Code ('Code Injection') vulnerability in Smackcoders WP Ultimate Exporter allows PHP Remote File Inclusion.This issue affects WP Ultimate Exporter: from n/a through …
|
CWE-94
Code Injection
|
CVE-2024-56278
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
884
|
- |
|
-
|
-
|
Missing Authorization vulnerability in WPForms Contact Form by WPForms allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Contact Form by WPForms: from n/a thr…
|
CWE-862
Missing Authorization
|
CVE-2024-56276
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
885
|
- |
|
-
|
-
|
Server-Side Request Forgery (SSRF) vulnerability in Envato Envato Elements allows Server Side Request Forgery.This issue affects Envato Elements: from n/a through 2.0.14.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-56275
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
886
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Astra Widgets allows Stored XSS.This issue affects Astra Widgets: from n/a throu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-56274
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
887
|
- |
|
-
|
-
|
Missing Authorization vulnerability in WPvivid Backup & Migration WPvivid Backup and Migration allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPvivid Backup and Mi…
|
CWE-862
Missing Authorization
|
CVE-2024-56273
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
888
|
- |
|
-
|
-
|
Missing Authorization vulnerability in SecureSubmit WP SecureSubmit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP SecureSubmit: from n/a through 1.5.16.
|
CWE-862
Missing Authorization
|
CVE-2024-56271
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
889
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ClickWhale ClickWhale – Link Manager, Link Shortener and Click Tracker for Affiliate Links & Link…
|
CWE-89
SQL Injection
|
CVE-2024-51715
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
890
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ? ?? (Minjun Kim) NAVER Analytics allows Stored XSS.This issue affects NAVER Analytics: from n/a …
|
CWE-79
Cross-site Scripting
|
CVE-2024-51700
|
2025-01-7 20:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|