CVE-2024-13832 – Elementor Ultra Addons Lite WordPress Information Exposure
CVE ID : CVE-2024-13832 Published : Feb. 28, 2025, 9:15 a.m. | 59 minutes ago Description : The Ultra Addons Lite for Elementor plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.1.8 via the ‘ut_elementor’ shortcode due to insufficient restrictions on which posts can be included. This makes it […]
CVE-2024-9019 – SecuPress Free WordPress Stored Cross-Site Scripting
CVE ID : CVE-2024-9019 Published : Feb. 28, 2025, 9:15 a.m. | 59 minutes ago Description : The SecuPress Free — WordPress Security plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s secupress_check_ban_ips_form shortcode in all versions up to, and including, 2.2.5.3 due to insufficient input sanitization and output escaping on user supplied […]
CVE-2024-13851 – “WordPress Modal Portfolio Stored Cross-Site Scripting”
CVE ID : CVE-2024-13851 Published : Feb. 28, 2025, 9:15 a.m. | 59 minutes ago Description : The Modal Portfolio plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.7.4.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Administrator-level access and […]
CVE-2024-9193 – WHMpress WHMCS WordPress Integration Plugin Local File Inclusion Vulnerability
The WHMpress – WHMCS WordPress Integration Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 6.3-revision-0 via the whmpress_domain_search_ajax_extended_results() function. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This […]
CVE-2024-8425 – WooCommerce Ultimate Gift Card Remote File Upload Vulnerability
The following table lists the changes that have been made to the CVE-2024-8425 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 28, 2025 Action […]
CVE-2024-8420 – WordPress DHVC Form Plugin Privilege Escalation Vulnerability
The following table lists the changes that have been made to the CVE-2024-8420 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Feb. 28, 2025 Action […]
CVE-2024-13831 – WooCommerce Tabs for WordPress PHP Object Injection Vulnerability
CVE ID : CVE-2024-13831 Published : Feb. 28, 2025, 9:15 a.m. | 59 minutes ago Description : The Tabs for WooCommerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.0.0 via deserialization of untrusted input in the ‘product_has_custom_tabs’ function. This makes it possible for authenticated attackers, with Shop […]
CVE-2024-13716 – “WordPress Forex Calculators Plugin Unauthorized Data Modification Vulnerability”
CVE ID : CVE-2024-13716 Published : Feb. 28, 2025, 9:15 a.m. | 59 minutes ago Description : The Forex Calculators plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the ajax_settings_callback() function in all versions up to, and including, 1.3.5. This makes it possible for authenticated attackers, with […]
CVE-2024-13638 – WooCommerce Order Attachments Sensitive Information Exposure
CVE ID : CVE-2024-13638 Published : Feb. 28, 2025, 9:15 a.m. | 59 minutes ago Description : The Order Attachments for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.1 via the ‘uploads’ directory. This makes it possible for unauthenticated attackers to extract sensitive data stored insecurely […]
CVE-2024-13469 – WordPress PickPlugins Pricing Table Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-13469 Published : Feb. 28, 2025, 9:15 a.m. | 59 minutes ago Description : The Pricing Table by PickPlugins plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Button Link in all versions up to, and including, 1.12.10 due to insufficient input sanitization and output escaping. This makes it possible for […]