Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-7878 Cross-site Scripting vulnerability in Technowich WP Ulike
The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
technowich CWE-79
4.8
2024-09-25 CVE-2024-8668 Cross-site Scripting vulnerability in Hasthemes Woolentor - Woocommerce Elementor Addons + Builder
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to, and including, 2.9.7 due to insufficient input sanitization and output escaping.
network
low complexity
hasthemes CWE-79
5.4
2024-09-25 CVE-2024-8515 Cross-site Scripting vulnerability in Themesflat Addons for Elementor 2.0.0/2.1.2
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes.
network
low complexity
themesflat CWE-79
5.4
2024-09-25 CVE-2024-7617 Cross-site Scripting vulnerability in Itpathsolutions Contact Form to ANY API
The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fields in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping.
network
low complexity
itpathsolutions CWE-79
6.1
2024-09-25 CVE-2024-8549 Cross-site Scripting vulnerability in Xtendify Simple Calendar
The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2.
network
low complexity
xtendify CWE-79
6.1
2024-09-25 CVE-2024-8713 Cross-site Scripting vulnerability in Pierros Kodex Posts Likes 2.4.3
The Kodex Posts likes plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.5.0.
network
low complexity
pierros CWE-79
6.1
2024-09-25 CVE-2024-8741 Cross-site Scripting vulnerability in Outtheboxthemes Beam ME UP Scotty
The Beam me up Scotty – Back to Top Button plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.0.21.
network
low complexity
outtheboxthemes CWE-79
6.1
2024-09-25 CVE-2024-9024 Cross-site Scripting vulnerability in Braginteractive Material Design Icons
The Material Design Icons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mdi-icon shortcode in all versions up to, and including, 0.0.5 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
braginteractive CWE-79
5.4
2024-09-25 CVE-2024-9027 Cross-site Scripting vulnerability in Wpzoom Shortcodes
The WPZOOM Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'box' shortcode in all versions up to, and including, 1.0.5 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpzoom CWE-79
5.4
2024-09-25 CVE-2024-9028 Cross-site Scripting vulnerability in Devfarm WP GPX Maps
The WP GPX Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'sgpx' shortcode in all versions up to, and including, 1.7.08 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
devfarm CWE-79
5.4