1651
|
5.4 |
MEDIUM
Network
|
videowhisper
|
picture_gallery
|
The Picture Gallery – Frontend Image Uploads, AJAX Photo List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'videowhisper_pictures' shortcode in all versions up t…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13584
|
2025-01-25 03:20 |
2025-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1652
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in mgplugin Roi Calculator allows Stored XSS. This issue affects Roi Calculator: from n/a through 1.0.
|
CWE-352
Origin Validation Error
|
CVE-2025-24756
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1653
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in add-ons.org PDF Invoices for WooCommerce + Drag and Drop Template Builder allows Stored XSS. This…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24755
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1654
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutenberg Blocks by Ka…
|
CWE-862
Missing Authorization
|
CVE-2025-24753
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1655
|
- |
|
-
|
-
|
Missing Authorization vulnerability in GoDaddy CoBlocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CoBlocks: from n/a through 3.1.13.
|
CWE-862
Missing Authorization
|
CVE-2025-24751
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1656
|
- |
|
-
|
-
|
Missing Authorization vulnerability in ExactMetrics ExactMetrics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ExactMetrics: from n/a through 8.1.0.
|
CWE-862
Missing Authorization
|
CVE-2025-24750
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1657
|
- |
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker allows Stored XSS. This issue affects Popup Maker: from n/a through 1.20.…
|
CWE-79
Cross-site Scripting
|
CVE-2025-24746
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1658
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80.
|
CWE-352
Origin Validation Error
|
CVE-2025-24739
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1659
|
- |
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in NowButtons.com Call Now Button allows Cross Site Request Forgery. This issue affects Call Now Button: from n/a through 1.4.13.
|
CWE-352
Origin Validation Error
|
CVE-2025-24738
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1660
|
- |
|
-
|
-
|
Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Duplicator: from n/a through…
|
CWE-862
Missing Authorization
|
CVE-2025-24736
|
2025-01-25 03:15 |
2025-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|