1811
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The MAS Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1.7 due to insufficient input sanitization and output …
|
CWE-79
Cross-site Scripting
|
CVE-2024-12328
|
2025-01-8 18:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1812
|
7.5 |
HIGH
Network
-
|
-
|
The Cost Calculator Builder PRO plugin for WordPress is vulnerable to blind time-based SQL Injection via the ‘data’ parameter in all versions up to, and including, 3.2.15 due to insufficient escaping…
|
CWE-89
SQL Injection
|
CVE-2024-11939
|
2025-01-8 18:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1813
|
9.8 |
CRITICAL
Network
-
|
-
|
The AdForest theme for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.1.6. This is due to the plugin not properly validating a user's ide…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2024-11350
|
2025-01-8 18:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1814
|
4.4 |
MEDIUM
Network
|
-
|
-
|
The Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the maker title value of the Google Maps block in all…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12045
|
2025-01-8 17:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1815
|
9.8 |
CRITICAL
Network
-
|
-
|
The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for …
|
CWE-94
Code Injection
|
CVE-2024-11635
|
2025-01-8 17:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
1816
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Piotnet Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Heading widget in all versions up to, and including, 2.4.31 due to insufficient inp…
|
CWE-79
Cross-site Scripting
|
CVE-2024-9673
|
2025-01-8 16:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1817
|
- |
|
-
|
-
|
A vulnerability has been found in VIWIS LMS 9.11 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component File Upload. The manipulation of the argume…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2024-8002
|
2025-01-8 16:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1818
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'ha_cmc_text' parameter of the Happy Mouse Cursor in all versions up to, and including, 3.15.1…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12852
|
2025-01-8 16:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1819
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid, Carousel and Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the custom_attribut…
|
CWE-79
Cross-site Scripting
|
CVE-2024-12851
|
2025-01-8 16:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1820
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.6.2 via the 'duplicate' function. Th…
|
CWE-200
Information Exposure
|
CVE-2024-12584
|
2025-01-8 16:15 |
2025-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|