821
|
5.5 |
MEDIUM
Network
|
-
|
-
|
The Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ays_sections[5][questions][8][title]’ parameter in all versions up to, and including, 5.1.3.3 due to insuff…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13505
|
2025-01-26 21:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
822
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WC Affiliate – A Complete WooCommerce Affiliate Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via any parameter in all versions up to, and including, 2.4 due to insu…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12334
|
2025-01-26 21:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
823
|
8.8 |
HIGH
Network
|
-
|
-
|
The Zox News theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'backup_options' and 'restore_option…
|
CWE-862
Missing Authorization
|
CVE-2024-11936
|
2025-01-26 21:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
824
|
8.8 |
HIGH
Network
|
-
|
-
|
The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.2. This is due to missing or incorrect nonce valid…
|
CWE-352
Origin Validation Error
|
CVE-2024-11641
|
2025-01-26 21:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
825
|
5.3 |
MEDIUM
Network
-
|
-
|
The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.2.13 via the WordPress core search feature. This …
|
CWE-200
Information Exposure
|
CVE-2024-11090
|
2025-01-26 16:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
826
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Multiple Page Generator Plugin – MPG plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.0.5 via the 'mpg_download_file_by_link' function. Th…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2024-10705
|
2025-01-26 16:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
827
|
- |
|
-
|
-
|
Develocity (formerly Gradle Enterprise) before 2024.1.8 has Incorrect Access Control. Project-level access control configuration was introduced in Enterprise Config schema version 8. Migration functi…
|
-
|
CVE-2024-46881
|
2025-01-26 16:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
828
|
- |
|
-
|
-
|
Develocity (formerly Gradle Enterprise) before 2024.3.1 allows an attacker who has network access to a Develocity server to obtain the hashed password of the system user. The hash algorithm used by D…
|
-
|
CVE-2025-24858
|
2025-01-26 16:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
829
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘content’ parameter in all versions up to, and including, 8.8.0 (Business)…
|
CWE-79
Cross-site Scripting
|
CVE-2024-10636
|
2025-01-26 15:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
830
|
7.3 |
HIGH
Network
-
|
-
|
The Quiz Maker Business, Developer, and Agency plugins for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.8.0 (Business), up to, and including, 21.8.…
|
CWE-95
Eval Injection
|
CVE-2024-10633
|
2025-01-26 15:15 |
2025-01-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|