Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-11-13 CVE-2024-9059 Cross-site Scripting vulnerability in Royal-Elementor-Addons Royal Elementor Addons
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Maps widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping.
network
low complexity
royal-elementor-addons CWE-79
5.4
2024-11-13 CVE-2024-9668 Cross-site Scripting vulnerability in Royal-Elementor-Addons Royal Elementor Addons
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Countdown widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
royal-elementor-addons CWE-79
5.4
2024-11-13 CVE-2024-9682 Cross-site Scripting vulnerability in Royal-Elementor-Addons Royal Elementor Addons
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Form Builder widget in all versions up to, and including, 1.7.1001 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
royal-elementor-addons CWE-79
5.4
2024-11-13 CVE-2024-10877 Cross-site Scripting vulnerability in Advancedformintegration Advanced Form Integration
The AFI – The Easiest Integration Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.92.0.
network
low complexity
advancedformintegration CWE-79
6.1
2024-11-13 CVE-2024-52268 Cross-site Scripting vulnerability in Vektor-Inc VK ALL in ONE Expansion Unit
Cross-site scripting vulnerability exists in VK All in One Expansion Unit versions prior to 9.100.1.0.
network
low complexity
vektor-inc CWE-79
4.8
2024-11-13 CVE-2024-10684 Cross-site Scripting vulnerability in Kognetiks Chatbot
The Kognetiks Chatbot for WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'dir' parameter in all versions up to, and including, 2.1.7 due to insufficient input sanitization and output escaping.
network
low complexity
kognetiks CWE-79
6.1
2024-11-13 CVE-2024-10882 The Product Delivery Date for WooCommerce – Lite plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.8.0.
network
low complexity
CWE-79
6.1
2024-11-13 CVE-2024-10686 The Design for Contact Form 7 Style WordPress Plugin – CF7 WOW Styler plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'style_scheme' parameter in all versions up to, and including, 1.6.8 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
6.1
2024-11-13 CVE-2024-10850 The Razorpay Payment Button Elementor Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 1.2.5.
network
low complexity
CWE-79
6.1
2024-11-13 CVE-2024-10851 The Razorpay Payment Button Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.6.
network
low complexity
CWE-79
6.1