CVE-2024-13852 – WordPress Option Editor CSRF
The following table lists the changes that have been made to the CVE-2024-13852 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13848 – WordPress Reaction Buttons Plugin Stored Cross-Site Scripting Vulnerability
The following table lists the changes that have been made to the CVE-2024-13848 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13725 – Keap Official Opt-in Forms WordPress Local File Inclusion Vulnerability
The Keap Official Opt-in Forms plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.1 via the service parameter. This makes it possible for unauthenticated attackers to include PHP files on the server, allowing the execution of any PHP code in those files. This can be used to […]
CVE-2024-13687 – WordPress Team Builder Plugin Unauthenticated Data Modification Vulnerability
The following table lists the changes that have been made to the CVE-2024-13687 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13684 – WordPress Reset Plugin Cross-Site Request Forgery (CSRF) Vulnerability
The Reset plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.6. This is due to missing or incorrect nonce validation on the reset_db_page() function. This makes it possible for unauthenticated attackers to reset several tables in the database like comments, themes, plugins, and more via a forged […]
CVE-2024-13677 – GetBookingsWP WordPress Privilege Escalation Vulnerability
The GetBookingsWP – Appointments Booking Calendar Plugin For WordPress plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.1.27. This is due to the plugin not properly validating a user’s identity prior to updating their details like email. This makes it possible for authenticated attackers, with […]
CVE-2024-13622 – WooCommerce File Uploads Sensitive Information Exposure
The following table lists the changes that have been made to the CVE-2024-13622 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13609 – WordPress 1-Click Migration Plugin Sensitive Information Exposure
The following table lists the changes that have been made to the CVE-2024-13609 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13587 – Zigaform WordPress Stored Cross-Site Scripting (XSS)
The following table lists the changes that have been made to the CVE-2024-13587 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]
CVE-2024-13595 – WordPress Simple Signup Form SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2024-13595 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 18, 2025 Action […]