CVE-2024-11376 – WordPress s2Member Reflected Cross-Site Scripting

CVE ID : CVE-2024-11376 Published : Feb. 18, 2025, 8:15 a.m. | 38 minutes ago Description : The s2Member – Excellent for All Kinds of Memberships, Content Restriction Paywalls & Member Access Subscriptions plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all […]

CVE-2024-57964 – HVAC Energy Saving Program DLL Loading Remote Code Execution/Information Disclosure Vulnerability

The following table lists the changes that have been made to the CVE-2024-57964 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]

CVE-2024-57963 – USB-CONVERTERCABLE DRIVER DLL Loading Vulnerability

The following table lists the changes that have been made to the CVE-2024-57963 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]

CVE-2024-13523 – MemorialDay WordPress CSRF

The following table lists the changes that have been made to the CVE-2024-13523 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]

CVE-2024-45320 – Canon DocuPrint MFP Out-of-bounds Write Denial-of-Service Vulnerability

The following table lists the changes that have been made to the CVE-2024-45320 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]

CVE-2024-13556 – “WordPress Affiliate Links PHP Object Injection Vulnerability”

CVE ID : CVE-2024-13556 Published : Feb. 18, 2025, 6:15 a.m. | 37 minutes ago Description : The Affiliate Links: WordPress Plugin for Link Cloaking and Link Management plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.1 via deserialization of untrusted input from an file export. This makes […]

CVE-2024-13438 – “SpeedSize WordPress Plugin CSRF Vulnerability”

CVE ID : CVE-2024-13438 Published : Feb. 18, 2025, 6:15 a.m. | 37 minutes ago Description : The SpeedSize Image & Video AI-Optimizer plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.1. This is due to missing or incorrect nonce validation on the ‘speedsize_clear_css_cache_action’ function. This makes it […]

CVE-2024-13315 – Shopwarden WooCommerce Cross-Site Request Forgery (CSRF)

CVE ID : CVE-2024-13315 Published : Feb. 18, 2025, 6:15 a.m. | 37 minutes ago Description : The Shopwarden – Automated WooCommerce monitoring & testing plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.11. This is due to missing or incorrect nonce validation on the save_setting() function. This […]

CVE-2025-0805 – WordPress Mortgage Calculator Stored Cross-Site Scripting

The following table lists the changes that have been made to the CVE-2025-0805 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]

CVE-2025-0796 – WordPress Mortgage Lead Capture System CSRF Vulnerability

The following table lists the changes that have been made to the CVE-2025-0796 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]