Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-26 CVE-2024-9177 Cross-site Scripting vulnerability in Themedy Toolbox
The Themedy Toolbox plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's themedy_col, themedy_social_link, themedy_alertbox, and themedy_pullleft shortcodes in all versions up to, and including, 1.0.14, and up to, and including 1.0.15 for the plugin's themedy_button shortcode due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
themedy CWE-79
5.4
2024-09-26 CVE-2024-7107 Files or Directories Accessible to External Parties vulnerability in Nationalkeep Cybermath 1.4
Files or Directories Accessible to External Parties vulnerability in National Keep Cyber Security Services CyberMath allows Collect Data from Common Resource Locations.This issue affects CyberMath: before CYBM.240816253.
network
low complexity
nationalkeep CWE-552
7.5
2024-09-26 CVE-2024-7108 Incorrect Authorization vulnerability in Nationalkeep Cybermath 1.4
Incorrect Authorization vulnerability in National Keep Cyber Security Services CyberMath allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects CyberMath: before CYBM.240816253.
network
low complexity
nationalkeep CWE-863
critical
9.8
2024-09-26 CVE-2024-8633 Cross-site Scripting vulnerability in 10Web Form Maker
The Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.15.27 due to insufficient input sanitization and output escaping.
network
low complexity
10web CWE-79
4.8
2024-09-26 CVE-2024-8126 Unrestricted Upload of File with Dangerous Type vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8.
network
low complexity
advancedfilemanager CWE-434
8.8
2024-09-26 CVE-2024-8704 Path Traversal vulnerability in Advancedfilemanager Advanced File Manager
The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter.
network
low complexity
advancedfilemanager CWE-22
7.2
2024-09-26 CVE-2024-8725 Unrestricted Upload of File with Dangerous Type vulnerability in Advancedfilemanager Advanced File Manager
Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions.
network
low complexity
advancedfilemanager CWE-434
5.4
2024-09-26 CVE-2022-4541 Cross-site Scripting vulnerability in Nitinmaurya Wordpress Visitors 1.0
The WordPress Visitors plugin for WordPress is vulnerable to Stored Cross-Site Scripting via a spoofed HTTP Header value in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping.
network
low complexity
nitinmaurya CWE-79
6.1
2024-09-26 CVE-2024-9115 Cross-site Scripting vulnerability in Chetanvaghela Common Tools for Site
The Common Tools for Site plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.2 due to insufficient input sanitization and output escaping.
network
low complexity
chetanvaghela CWE-79
5.4
2024-09-26 CVE-2024-9117 Cross-site Scripting vulnerability in Mapplic 1.0
The Mapplic Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping.
network
low complexity
mapplic CWE-79
5.4