Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-8910 Unspecified vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.6.5 via the render function in includes/widgets/htmega_accordion.php.
network
low complexity
hasthemes
4.3
2024-09-25 CVE-2024-6845 Missing Authorization vulnerability in Smartsearchwp
The Chatbot with ChatGPT WordPress plugin before 2.4.6 does not have proper authorization in one of its REST endpoint, allowing unauthenticated users to retrieve the encoded key and then decode it, thereby leaking the OpenAI API key
network
low complexity
smartsearchwp CWE-862
5.3
2024-09-25 CVE-2024-7878 Cross-site Scripting vulnerability in Technowich WP Ulike
The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
technowich CWE-79
4.8
2024-09-25 CVE-2024-7892 Cross-Site Request Forgery (CSRF) vulnerability in Vladyslavbondarenko Adstxt
The adstxt Plugin WordPress plugin through 1.0.0 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
network
low complexity
vladyslavbondarenko CWE-352
4.3
2024-09-25 CVE-2024-8658 Missing Authorization vulnerability in Mycred
The myCred – Loyalty Points and Rewards plugin for WordPress and WooCommerce – Give Points, Ranks, Badges, Cashback, WooCommerce rewards, and WooCommerce credits for Gamification plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the mycred_update_database() function in all versions up to, and including, 2.7.3.
network
low complexity
mycred CWE-862
5.3
2024-09-25 CVE-2024-8275 SQL Injection vulnerability in Stellarwp the Events Calendar
The The Events Calendar plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'tribe_has_next_event' function in all versions up to, and including, 6.6.4 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
stellarwp CWE-89
critical
9.8
2024-09-25 CVE-2024-8668 Cross-site Scripting vulnerability in Hasthemes Woolentor - Woocommerce Elementor Addons + Builder
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to, and including, 2.9.7 due to insufficient input sanitization and output escaping.
network
low complexity
hasthemes CWE-79
5.4
2024-09-25 CVE-2024-7385 SQL Injection vulnerability in Freelancer-Coder Wordpress Simple Html Sitemap
The WordPress Simple HTML Sitemap plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 3.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
freelancer-coder CWE-89
7.2
2024-09-25 CVE-2024-8514 Deserialization of Untrusted Data vulnerability in Prisna Google Website Translator
The Prisna GWT – Google Website Translator plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.4.11 via deserialization of untrusted input from the 'prisna_import' parameter.
network
low complexity
prisna CWE-502
7.2
2024-09-25 CVE-2024-8515 Cross-site Scripting vulnerability in Themesflat Addons for Elementor 2.0.0/2.1.2
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes.
network
low complexity
themesflat CWE-79
5.4