1931
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Print Invoice & Delivery Notes for WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'wcdn_remove_shoplogo' AJAX action …
|
CWE-862
Missing Authorization
|
CVE-2024-12210
|
2024-12-24 15:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1932
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Bitcoin Lightning Publisher for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versi…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12100
|
2024-12-24 15:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1933
|
- |
|
-
|
-
|
The Exhibit to WP Gallery WordPress plugin through 0.0.2 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be use…
|
-
|
CVE-2024-12096
|
2024-12-24 15:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1934
|
5.3 |
MEDIUM
Network
-
|
-
|
The Advanced Google reCAPTCHA plugin for WordPress is vulnerable to IP unblocking in all versions up to, and including, 1.25. This is due to the plugin not utilizing a strong unique key when generati…
|
CWE-340
Generation of Predictable Numbers or Identifiers
|
CVE-2024-12034
|
2024-12-24 15:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1935
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The NinjaTeam Chat for Telegram plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'njtele_button shortcode in all versions up to, and including, 1.0 due to insufficie…
|
CWE-79
Cross-site Scripting
|
CVE-2024-11885
|
2024-12-24 15:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1936
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The WP-Appbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' parameter in all versions up to, and including, 4.5.3 due to insufficient input sanitization and outp…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12710
|
2024-12-24 14:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1937
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The WC Price History for Omnibus plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on several AJAX actions in all versions up to, and including, 2.1.3. This …
|
CWE-862
Missing Authorization
|
CVE-2024-12617
|
2024-12-24 14:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1938
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The ShMapper by Teplitsa plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'shmMap' shortcode in all versions up to, and including, 1.4.18 due to insufficient input s…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12518
|
2024-12-24 14:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1939
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Optio Dentistry plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'optio-lightbox' shortcode in all versions up to, and including, 2.1 due to insufficient input s…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12507
|
2024-12-24 14:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1940
|
6.5 |
MEDIUM
Network
-
|
-
|
The ELEX WooCommerce Dynamic Pricing and Discounts plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the elex_dp_export_rules() and elex_dp_import…
|
CWE-862
Missing Authorization
|
CVE-2024-12266
|
2024-12-24 14:15 |
2024-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|