Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-26 CVE-2024-8704 Path Traversal vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter.
network
low complexity
advancedfilemanager CWE-22
7.2
2024-09-26 CVE-2024-8725 Unrestricted Upload of File with Dangerous Type vulnerability in Advancedfilemanager Advanced File Manager
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions.
network
low complexity
advancedfilemanager CWE-434
5.4
2024-09-26 CVE-2022-4541 Cross-site Scripting vulnerability in Nitinmaurya Wordpress Visitors 1.0
The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping.
network
low complexity
nitinmaurya CWE-79
6.1
2024-09-26 CVE-2024-9115 Cross-site Scripting vulnerability in Chetanvaghela Common Tools for Site
The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping.
network
low complexity
chetanvaghela CWE-79
5.4
2024-09-26 CVE-2024-9117 Cross-site Scripting vulnerability in Mapplic 1.0
The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping.
network
low complexity
mapplic CWE-79
5.4
2024-09-26 CVE-2024-9125 Cross-site Scripting vulnerability in Kingblack King IE
The king_IE plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping.
network
low complexity
kingblack CWE-79
5.4
2024-09-26 CVE-2024-9127 Cross-site Scripting vulnerability in Codecabin Super Testimonials 3.0.0
The Super Testimonials plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘alignment’ parameter in all versions up to, and including, 3.0.0 due to insufficient input sanitization and output escaping.
network
low complexity
codecabin CWE-79
5.4
2024-09-26 CVE-2024-9173 Cross-site Scripting vulnerability in Alefypimentel GF Custom Style 2.0
The GF Custom Style plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0 due to insufficient input sanitization and output escaping.
network
low complexity
alefypimentel CWE-79
5.4
2024-09-26 CVE-2024-9198 Cross-site Scripting vulnerability in Clibomanager Clibo Manager 1.1.9.1
Vulnerability in Clibo Manager v1.1.9.1 that could allow an attacker to execute an stored Cross-Site Scripting (stored XSS ) by uploading a malicious .svg image in the section: Profile > Profile picture.
network
low complexity
clibomanager CWE-79
5.4
2024-09-26 CVE-2024-9199 Unspecified vulnerability in Clibomanager Clibo Manager 1.1.9.2
Rate limit vulnerability in Clibo Manager v1.1.9.2 that could allow an attacker to send a large number of emails to the victim in a short time, affecting availability and leading to a denial of service (DoS).
network
low complexity
clibomanager
7.5