Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-10-11 CVE-2024-47830 Server-Side Request Forgery (SSRF) vulnerability in Plane
Plane is an open-source project management tool.
network
low complexity
plane CWE-918
5.8
2024-10-11 CVE-2024-7514 The WordPress Comments Import & Export plugin for WordPress is vulnerable to to arbitrary file read due to insufficient file path validation during the comments import process, in versions up to, and including, 2.3.7.
network
low complexity
CWE-22
6.5
2024-10-11 CVE-2024-8913 The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.6.11 via the render function in modules/widgets/tp_accordion.php.
network
low complexity
CWE-200
4.3
2024-10-11 CVE-2024-9051 The WP Ultimate Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wpupg-grid-with-filters shortcode in all versions up to, and including, 3.9.3 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
6.4
2024-10-11 CVE-2024-9211 The FULL – Cliente plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.1.22.
network
low complexity
CWE-79
6.1
2024-10-11 CVE-2024-9221 The Tainacan plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 0.21.10.
network
low complexity
CWE-79
6.1
2024-10-11 CVE-2024-9232 The Download Plugins and Themes in ZIP from Dashboard plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.1.
network
low complexity
CWE-79
6.1
2024-10-11 CVE-2024-9346 The Embed videos and respect privacy plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'v' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2024-10-11 CVE-2024-9436 The PublishPress Revisions: Duplicate Posts, Submit, Approve and Schedule Content Changes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.5.14.
network
low complexity
CWE-79
6.1
2024-10-11 CVE-2024-9538 The ShopLentor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.8 via the 'render' function in includes/addons/wl_faq.php.
network
low complexity
CWE-200
4.3