CVE-2024-13341 – MultiLoca WooCommerce Multi Locations Inventory Management Plugin SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-13341 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 01, 2025 Action […]
CVE-2024-11829 – Elementor Addons Stored Cross-Site Scripting
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Widget’s searchable_label parameter in all versions up to, and including, 6.1.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level […]
BeyondTrust Zero-Day Breach Exposes 17 SaaS Customers via Compromised API Key
BeyondTrust Zero-Day Breach Exposes 17 SaaS Customers via Compromised API Key BeyondTrust has revealed it completed an investigation into a recent cybersecurity incident that targeted some of the company’s Remote Support SaaS instances by making use of a compromised API key. Th … Read more Published Date: Feb 01, 2025 (1 hour, 12 minutes ago) Vulnerabilities has […]
CVE-2025-0366 – “Jupiter X Core WordPress Remote Code Execution Vulnerability”
The Jupiter X Core plugin for WordPress is vulnerable to Local File Inclusion to Remote Code Execution in all versions up to, and including, 4.8.7 via the get_svg() function. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any […]
CVE-2024-13099 – Widget4Call WordPress Plugin Reflected Cross-Site Scripting Vuln
The following table lists the changes that have been made to the CVE-2024-13099 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 01, 2025 Action […]
CVE-2025-0365 – Jupiter X Core WordPress Directory Traversal Vulnerability
The Jupiter X Core plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.8.7 via the inline SVG feature. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information.
CVE-2024-13098 – WordPress Email Newsletter Plugin Reflected Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2024-13098 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 01, 2025 Action […]
CVE-2024-13097 – WordPress Finance Plugin Reflected Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2024-13097 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 01, 2025 Action […]
CVE-2024-13096 – WordPress Finance CSRF Stored XSS
The following table lists the changes that have been made to the CVE-2024-13096 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 01, 2025 Action […]
CVE-2024-12768 – WordPress Responsive Iframe Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2024-12768 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 01, 2025 Action […]