CVE-2024-13882 – WordPress Aiomatic Arbitrary File Upload Vulnerability

CVE ID : CVE-2024-13882 Published : March 8, 2025, 9:15 a.m. | 28 minutes ago Description : The Aiomatic – Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ‘aiomatic_generate_featured_image’ function in all versions […]

CVE-2024-10321 – Elementor WidgetKit Sensitive Information Exposure

CVE ID : CVE-2024-10321 Published : March 8, 2025, 9:15 a.m. | 28 minutes ago Description : The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.5.4 in elements/advanced-tab/template/view.php. This makes it possible for authenticated attackers, with Contributor-level access and above, to […]

CVE-2024-11087 – Discord Social Login WordPress Plugin Authentication Bypass

CVE ID : CVE-2024-11087 Published : March 8, 2025, 7:15 a.m. | 15 minutes ago Description : The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) Pro Addon plugin for WordPress is vulnerable to authentication bypass in all versions up to, and including, 200.3.9. This is due to insufficient verification on the user being returned […]

CVE-2024-13844 – WordPress Post SMTP SQL Injection

CVE ID : CVE-2024-13844 Published : March 8, 2025, 6:15 a.m. | 1 hour, 15 minutes ago Description : The Post SMTP plugin for WordPress is vulnerable to generic SQL Injection via the ‘columns’ parameter in all versions up to, and including, 3.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation […]

CVE-2024-13826 – “WordPress Email Keep CSRF”

CVE ID : CVE-2024-13826 Published : March 8, 2025, 6:15 a.m. | 1 hour, 15 minutes ago Description : The Email Keep WordPress plugin through 1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack Severity: 0.0 | NA […]

CVE-2024-13825 – WordPress Email Keep Reflected Cross-Site Scripting

CVE ID : CVE-2024-13825 Published : March 8, 2025, 6:15 a.m. | 1 hour, 15 minutes ago Description : The Email Keep WordPress plugin through 1.1 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. […]

CVE-2024-12119 – FooGallery WordPress Stored Cross-Site Scripting (XSS) Vulnerability

CVE ID : CVE-2024-12119 Published : March 8, 2025, 6:15 a.m. | 1 hour, 15 minutes ago Description : The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the default_gallery_title_size parameter in all versions up to, and including, 2.4.29 due to insufficient input sanitization […]

CVE-2024-12114 – FooGallery WordPress Insecure Direct Object Reference

CVE ID : CVE-2024-12114 Published : March 8, 2025, 6:15 a.m. | 1 hour, 15 minutes ago Description : The FooGallery – Responsive Photo Gallery, Image Viewer, Justified, Masonry & Carousel plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.29 via the foogallery_attachment_modal_save AJAX action due to missing […]