CVE-2024-9502 – Elementor Addons WordPress Stored Cross-Site Scripting

CVE ID : CVE-2024-9502 Published : Jan. 7, 2025, 7:15 a.m. | 29 minutes ago Description : The Master Addons – Elementor Addons with White Label, Free Widgets, Hover Effects, Conditions, & Animations plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Tooltip module in all versions up to, and including, 2.0.6.7 due […]

CVE-2024-12781 – Aurum – WordPress & WooCommerce Shopping Theme Remote Data Tampering

CVE ID : CVE-2024-12781 Published : Jan. 7, 2025, 7:15 a.m. | 29 minutes ago Description : The Aurum – WordPress & WooCommerce Shopping Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ‘lab_1cl_demo_install_package_content’ function in all versions up to, and including, 4.0.2. This makes it […]

CVE-2024-12624 – Elementor Sina Extension Stored Cross-Site Scripting Vulnerability

CVE ID : CVE-2024-12624 Published : Jan. 7, 2025, 7:15 a.m. | 29 minutes ago Description : The Sina Extension for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s Sina Image Differ widget in all versions up to, and including, 3.5.91 due to insufficient input sanitization and output escaping on user […]

CVE-2024-9354 – Estatik Mortgage Calculator (WordPress) Reflected Cross-Site Scripting (XSS)

CVE ID : CVE-2024-9354 Published : Jan. 7, 2025, 7:15 a.m. | 29 minutes ago Description : The Estatik Mortgage Calculator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘color’ parameter in all versions up to, and including, 2.0.11 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated […]

CVE-2024-12499 – “WordPress WP jQuery DataTable Stored Cross-Site Scripting (XSS)”

CVE ID : CVE-2024-12499 Published : Jan. 7, 2025, 7:15 a.m. | 29 minutes ago Description : The WP jQuery DataTable plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘wp_jdt’ shortcode in all versions up to, and including, 4.0.1 due to insufficient input sanitization and output escaping on user supplied attributes. This […]

CVE-2024-12495 – “WordPress Bootstrap Blocks Stored Cross-Site Scripting”

CVE ID : CVE-2024-12495 Published : Jan. 7, 2025, 7:15 a.m. | 29 minutes ago Description : The Bootstrap Blocks for WP Editor v2 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘gtb-bootstrap/column’ block in all versions up to, and including, 2.5.0 due to insufficient input sanitization and output escaping. This makes it […]

CVE-2024-12437 – WordPress Marketplace Items Stored Cross-Site Scripting Attack

CVE ID : CVE-2024-12437 Published : Jan. 7, 2025, 7:15 a.m. | 29 minutes ago Description : The Marketplace Items plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘envato’ shortcode in all versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes […]

CVE-2024-11764 – WordPress Solar Wizard Lite Stored Cross-Site Scripting

CVE ID : CVE-2024-11764 Published : Jan. 7, 2025, 7:15 a.m. | 29 minutes ago Description : The Solar Wizard Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘solar_wizard’ shortcode in all versions up to, and including, 1.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This […]

CVE-2024-11282 – WordPress Passster Sensitive Information Exposure Vulnerability

CVE ID : CVE-2024-11282 Published : Jan. 7, 2025, 7:15 a.m. | 29 minutes ago Description : The Passster – Password Protect Pages and Content plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.2.10 via the WordPress core search feature. This makes it possible for unauthenticated attackers to […]