CVE-2024-13649 – Elementor Xpro Addons for WordPress Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2024-13649 Published : March 8, 2025, 12:15 p.m. | 1 hour, 28 minutes ago Description : The 140+ Widgets | Xpro Addons For Elementor – FREE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets in all versions up to, and including, 1.4.6.7 due to insufficient input sanitization and output escaping. […]
CVE-2024-11640 – VikRentCar WordPress Car Rental Management System CSRF Arbitrary File Upload Vulnerability
The following table lists the changes that have been made to the CVE-2024-11640 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 08, 2025 Action […]
CVE-2025-1783 – WordPress Gallery Styles Stored Cross-Site Scripting
The following table lists the changes that have been made to the CVE-2025-1783 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 08, 2025 Action […]
CVE-2025-1325 – WordPress WP-Recall Arbitrary Shortcode Execution Vulnerability
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to arbitrary shortcode execution due to a missing capability check on the ‘rcl_preview_post’ AJAX endpoint in all versions up to, and including, 16.26.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.
CVE-2025-1324 – WordPress WP-Recall Stored Cross-Site Scripting Vulnerability
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin’s ‘public-form’ shortcode in all versions up to, and including, 16.26.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to […]
CVE-2025-1323 – WordPress WP-Recall SQL Injection Vulnerability
The following table lists the changes that have been made to the CVE-2025-1323 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 08, 2025 Action […]
CVE-2025-1322 – WordPress WP-Recall Information Exposure Vulnerability
The WP-Recall – Registration, Profile, Commerce & More plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 16.26.10 via the ‘feed’ shortcode due to insufficient restrictions on which posts can be included. This makes it possible for unauthenticated attackers to view data from password protected, private, or draft posts […]
CVE-2024-13359 – WooCommerce File Upload Vulnerability
The following table lists the changes that have been made to the CVE-2024-13359 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Mar. 08, 2025 Action […]
CVE-2025-1287 – Elementor Addons Stored Cross-Site Scripting Vulnerability
CVE ID : CVE-2025-1287 Published : March 8, 2025, 9:15 a.m. | 28 minutes ago Description : The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Countdown, Syntax Highlighter, and Page Scroll widgets in all versions up to, and […]
CVE-2025-0177 – Javo Core WordPress Privilege Escalation
CVE ID : CVE-2025-0177 Published : March 8, 2025, 9:15 a.m. | 28 minutes ago Description : The Javo Core plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 3.0.0.080. This is due to the plugin allowing users who are registering new accounts to set their own role. This makes […]