Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-01-17 CVE-2024-12203 The RSS Icon Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link_color’ parameter in all versions up to, and including, 5.2 due to insufficient input sanitization and output escaping.
network
high complexity
CWE-79
4.4
2025-01-17 CVE-2024-12466 The Proofreading plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'nonce' parameter in all versions up to, and including, 1.2.1.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2025-01-17 CVE-2024-12508 The Glofox Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'glofox' and 'glofox_lead_capture ' shortcodes in all versions up to, and including, 2.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2025-01-17 CVE-2024-12598 The MyBookProgress by Stormhill Media plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘book’ parameter in all versions up to, and including, 1.0.8 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2025-01-17 CVE-2024-12637 The Moving Users plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.05 via the export functionality.
network
low complexity
CWE-200
5.3
2025-01-17 CVE-2024-13366 The Sandbox plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'debug' parameter in all versions up to, and including, 0.4 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2025-01-17 CVE-2024-13367 The Sandbox plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the export_download action in all versions up to, and including, 0.4.
network
low complexity
CWE-862
6.5
2025-01-17 CVE-2024-13386 The quote-posttype-plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Author field in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.4
2025-01-17 CVE-2024-10799 The Eventer plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.9.7 via the eventer_woo_download_tickets() function.
network
low complexity
CWE-22
6.5
2025-01-17 CVE-2024-13333 The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13.
network
high complexity
CWE-434
7.5