Vulnerabilities
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-09-13 | CVE-2024-5869 | Cross-site Scripting vulnerability in Arnoldgoodway Neighborly The Neighborly theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-13 | CVE-2024-5870 | Cross-site Scripting vulnerability in Arnoldgoodway Tweaker5 The Tweaker5 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter within the theme's Button shortcode in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-13 | CVE-2024-5884 | Cross-site Scripting vulnerability in Allprices Beauty The Beauty theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘tpl_featured_cat_id’ parameter in all versions up to, and including, 1.1.4 due to insufficient input sanitization and output escaping. | 5.4 |
2024-09-13 | CVE-2024-6544 | Information Exposure Through an Error Message vulnerability in Coffee2Code Custom Post Limits The Custom Post Limits plugin for WordPress is vulnerable to full path disclosure in all versions up to, and including, 4.4.1. | 5.3 |
2024-09-13 | CVE-2024-7423 | Cross-Site Request Forgery (CSRF) vulnerability in XWP Stream The Stream plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.0.1. | 8.8 |
2024-09-13 | CVE-2024-8242 | Unrestricted Upload of File with Dangerous Type vulnerability in Inspireui Mstore API The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the update_user_profile() function in all versions up to, and including, 4.15.3. | 8.8 |
2024-09-13 | CVE-2024-8269 | Unspecified vulnerability in Inspireui Mstore API The MStore API – Create Native Android & iOS Apps On The Cloud plugin for WordPress is vulnerable to unauthorized user registration in all versions up to, and including, 4.15.3. | 6.5 |
2024-09-13 | CVE-2024-8714 | Cross-site Scripting vulnerability in Slicewp Affiliate Program Suite The WordPress Affiliates Plugin — SliceWP Affiliates plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.1.20. | 6.1 |
2024-09-13 | CVE-2024-8730 | Cross-site Scripting vulnerability in Cvstech Exit Notifier The Exit Notifier plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.9.1. | 6.1 |
2024-09-13 | CVE-2024-8731 | Cross-site Scripting vulnerability in Leira Cron Jobs The Cron Jobs plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.9. | 6.1 |