1771
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_ajax_toggle_ae and vcita_ajax_togg…
|
CWE-862
Missing Authorization
|
CVE-2024-13717
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1772
|
7.2 |
HIGH
Network
-
|
-
|
The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42…
|
CWE-79
Cross-site Scripting
|
CVE-2024-13504
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1773
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'niwoosc_ajax' AJAX endpoint in all versions up to, and incl…
|
CWE-862
Missing Authorization
|
CVE-2024-13424
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1774
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all version…
|
CWE-862
Missing Authorization
|
CVE-2024-13415
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1775
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function …
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2024-13216
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1776
|
- |
|
-
|
-
|
The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could al…
|
-
|
CVE-2024-13101
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1777
|
- |
|
-
|
-
|
The OPSI Israel Domestic Shipments WordPress plugin through 2.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou…
|
-
|
CVE-2024-13100
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1778
|
- |
|
-
|
-
|
The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even w…
|
-
|
CVE-2024-12872
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1779
|
- |
|
-
|
-
|
The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used again…
|
-
|
CVE-2024-12275
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1780
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in all versions up to, and includin…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11886
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|