601
|
8.8 |
HIGH
Network
|
-
|
-
|
The SMS Alert Order Notifications – WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the …
New
|
CWE-862
Missing Authorization
|
CVE-2024-11725
|
2025-01-7 16:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
602
|
5.3 |
MEDIUM
Network
-
|
-
|
The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search featu…
New
|
CWE-200
Information Exposure
|
CVE-2024-11282
|
2025-01-7 16:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
603
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'socialrocket-floating' shortcode in all versions up to, and including, 1.…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-9702
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
604
|
5.3 |
MEDIUM
Network
-
|
-
|
The Social Rocket – Social Sharing Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the tweet_settings_save() and tweet_settings_upd…
New
|
CWE-862
Missing Authorization
|
CVE-2024-9697
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
605
|
- |
|
-
|
-
|
Seth Fogie, member of AXIS Camera Station Pro Bug Bounty Program, has found that it is possible for an authenticated malicious client to tamper with audit log creation in AXIS Camera Station, or perf…
New
|
-
|
CVE-2024-7696
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
606
|
7.5 |
HIGH
Network
-
|
-
|
The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download AJAX action. This mak…
New
|
CWE-22
Path Traversal
|
CVE-2024-12849
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
607
|
7.1 |
HIGH
Network
|
-
|
-
|
The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘page parameter in all versions up to, and including, 5…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-12633
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
608
|
8.6 |
HIGH
Network
-
|
-
|
The Host PHP Info plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 1.0.4…
New
|
CWE-862
Missing Authorization
|
CVE-2024-12535
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
609
|
8.8 |
HIGH
Network
|
-
|
-
|
The Post Saint: ChatGPT, GPT4, DALL-E, Stable Diffusion, Pexels, Dezgo AI Text & Image Generator plugin for WordPress is vulnerable to arbitrary files uploads due to a missing capability check and fi…
New
|
CWE-94
Code Injection
|
CVE-2024-12471
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
610
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Chatroll Live Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'chatroll' shortcode in all versions up to, and including, 2.5.0 due to insufficient input sa…
New
|
CWE-79
Cross-site Scripting
|
CVE-2024-12464
|
2025-01-7 15:15 |
2025-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|