Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-26 | CVE-2024-8704 | Path Traversal vulnerability in Advancedfilemanager Advanced File Manager The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. | 7.2 |
2024-09-26 | CVE-2024-8725 | Unrestricted Upload of File with Dangerous Type vulnerability in Advancedfilemanager Advanced File Manager Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. | 5.4 |
2024-09-26 | CVE-2022-4541 | Cross-site Scripting vulnerability in Nitinmaurya Wordpress Visitors 1.0 The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. | 6.1 |
2024-09-26 | CVE-2024-9115 | Cross-site Scripting vulnerability in Chetanvaghela Common Tools for Site The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-26 | CVE-2024-9117 | Cross-site Scripting vulnerability in Mapplic 1.0 The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-26 | CVE-2024-9125 | Cross-site Scripting vulnerability in Kingblack King IE The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-26 | CVE-2024-9127 | Cross-site Scripting vulnerability in Codecabin Super Testimonials 3.0.0 The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-26 | CVE-2024-9173 | Cross-site Scripting vulnerability in Alefypimentel GF Custom Style 2.0 The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-26 | CVE-2024-9198 | Cross-site Scripting vulnerability in Clibomanager Clibo Manager 1.1.9.1 Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture. | 5.4 |
2024-09-26 | CVE-2024-9199 | Unspecified vulnerability in Clibomanager Clibo Manager 1.1.9.2 Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of service (DoS). | 7.5 |