Page(s) : 1 ... 769 770 771 772 773 774 775 776 777 778 [779] 780 781 782 783 784 785 786 787 788 789 ... | Result(s) : 300103 |
Alerts
DATE | NAME | CATEGORIES | DETAIL | |
---|---|---|---|---|
N/A | 2025-03-08 | CVE-2024-13826 | cve | The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a... |
4.9 | 2025-03-08 | CVE-2024-13844 | cve | The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due to insufficient escaping on... |
9.8 | 2025-03-08 | CVE-2024-11087 | cve | The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and in... |
7.2 | 2025-03-08 | CVE-2024-13908 | cve | The SMTP by BestWebSoft plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'save_options' function in all versions... |
4.3 | 2025-03-08 | CVE-2024-10321 | cve | The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.4 in elements/adva... |
5.4 | 2025-03-08 | CVE-2024-13816 | cve | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to unauthorized access, modification, and los... |
8.8 | 2025-03-08 | CVE-2024-13882 | cve | The Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file... |
9.8 | 2025-03-08 | CVE-2025-0177 | cve | The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are regist... |
5.4 | 2025-03-08 | CVE-2025-1287 | cve | The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the C... |
9.8 | 2025-03-08 | CVE-2024-13359 | cve | The Product Input Fields for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the add_product_input_fields_to... |
4.3 | 2025-03-08 | CVE-2025-1322 | cve | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the 'fe... |
9.8 | 2025-03-08 | CVE-2025-1323 | cve | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to SQL Injection via the 'databeat' parameter in all versions up to, and incl... |
5.4 | 2025-03-08 | CVE-2025-1324 | cve | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'public-form' shortcode ... |
6.3 | 2025-03-08 | CVE-2025-1325 | cve | The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the 'rcl_pre... |
5.4 | 2025-03-08 | CVE-2025-1783 | cve | The Gallery Styles plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Gallery Block in all versions up to, and including, 1.3.4 due to insufficient input ... |
5.4 | 2025-03-08 | CVE-2025-1261 | cve | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to DOM-Based Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up... |
6.4 | 2025-03-08 | CVE-2024-12460 | cve | The Years Since – Timeless Texts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'years-since' shortcode in all versions up to,... |
6.5 | 2025-03-08 | CVE-2024-13774 | cve | The Wishlist for WooCommerce: Multi Wishlists Per Customer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.1.7. This is ... |
7.2 | 2025-03-08 | CVE-2024-13835 | cve | The Post Meta Data Manager plugin for WordPress is vulnerable to multisite privilege escalation in all versions up to, and including, 1.4.3. This is due to the plugin not proper... |
7.2 | 2025-03-08 | CVE-2024-13890 | cve | The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to allowing PHP code to be entered by all u... |
Page(s) : 1 ... 769 770 771 772 773 774 775 776 777 778 [779] 780 781 782 783 784 785 786 787 788 789 ... | Result(s) : 300103 |