401
|
7.5 |
HIGH
Network
|
-
|
-
|
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 …
|
CWE-22
Path Traversal
|
CVE-2024-13409
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
402
|
7.5 |
HIGH
Network
|
-
|
-
|
The Post Grid, Slider & Carousel Ultimate – with Shortcode, Gutenberg Block & Elementor Widget plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.6.10 …
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2024-13408
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
403
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Responsive Addons for Elementor – Free Elementor Addons Plugin and Elementor Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via HTML tags in several widgets in all ve…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13354
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
404
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Spexo Addons for Elementor – Free Elementor Addons, Widgets and Templates plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the tmpcoder_theme_install…
|
CWE-862
Missing Authorization
|
CVE-2024-13335
|
2025-01-24 20:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
405
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Simple Gallery with Filter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'c2tw_sgwf' shortcode in all versions up to, and including, 2.0 due to insufficient i…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13583
|
2025-01-24 19:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
406
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The BMLT Meeting Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bmlt_meeting_map' shortcode in all versions up to, and including, 2.6.1 due to insufficient in…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12494
|
2025-01-24 19:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
407
|
9.8 |
CRITICAL
Network
-
|
-
|
The Bootstrap Ultimate theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.4.9 via the path parameter. This makes it possible for unauthenticated attacke…
|
CWE-22
Path Traversal
|
CVE-2024-13545
|
2025-01-24 18:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
408
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Automate Hub Free by Sperse.IO plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.7.0. This is due to missing or incorrect nonce validation o…
|
CWE-352
Origin Validation Error
|
CVE-2024-13683
|
2025-01-24 16:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
409
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Form Builder CP plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter of the 'CP_EASY_FORM_WILL_APPEAR_HERE' shortcode in all versions up to, and including, 1.2.41 due to ins…
|
CWE-89
SQL Injection
|
CVE-2024-13680
|
2025-01-24 16:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
410
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Listamester plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'listamester' shortcode in all versions up to, and including, 2.3.4 due to insufficient input saniti…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13659
|
2025-01-24 15:15 |
2025-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|