981
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Ni Sales Commission For WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the 'niwoosc_ajax' AJAX endpoint in all versions up to, and incl…
|
CWE-862
Missing Authorization
|
CVE-2024-13424
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
982
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Food Menu – Restaurant Menu & Online Ordering for WooCommerce plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the response() function in all version…
|
CWE-862
Missing Authorization
|
CVE-2024-13415
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
983
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The HT Event – WordPress Event Manager Plugin for Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.7 via the 'render' function …
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2024-13216
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
984
|
- |
|
-
|
-
|
The WP MediaTagger WordPress plugin through 4.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could al…
|
-
|
CVE-2024-13101
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
985
|
- |
|
-
|
-
|
The OPSI Israel Domestic Shipments WordPress plugin through 2.6.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which cou…
|
-
|
CVE-2024-13100
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
986
|
- |
|
-
|
-
|
The Zalomení WordPress plugin through 1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even w…
|
-
|
CVE-2024-12872
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
987
|
- |
|
-
|
-
|
The Canvasflow for WordPress plugin through 1.5.5 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used again…
|
-
|
CVE-2024-12275
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
988
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Contact Form and Calls To Action by vcita plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'vCitaMeetingScheduler ' shortcode in all versions up to, and includin…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11886
|
2025-01-31 15:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
989
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Ticketmeo – Sell Tickets – Event Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 2.3.6 due to insuffi…
|
CWE-79
Cross-site Scripting
|
CVE-2025-0507
|
2025-01-31 14:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
990
|
9.8 |
CRITICAL
Network
-
|
-
|
The MultiVendorX – The Ultimate WooCommerce Multivendor Marketplace Solution plugin for WordPress is vulnerable to Limited Local File Inclusion in all versions up to, and including, 4.2.14 via the t…
|
CWE-22
Path Traversal
|
CVE-2025-0493
|
2025-01-31 14:15 |
2025-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|