Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-05-02 CVE-2024-2085 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' value in several widgets all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
hasthemes CWE-79
5.4
2024-05-02 CVE-2024-2273 Cross-site Scripting vulnerability in Kadencewp Gutenberg Blocks With AI
The Gutenberg Blocks by Kadence Blocks – Page Builder Features plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in all versions up to, and including, 3.2.34 due to insufficient input sanitization and output escaping.
network
low complexity
kadencewp CWE-79
5.4
2024-05-02 CVE-2024-2503 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Grid Widget in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping on user supplied tags.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-05-02 CVE-2024-2750 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the URL attribute of the Button widget in all versions up to, and including, 2.6.9.3 due to insufficient input sanitization and output escaping.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-05-02 CVE-2024-2751 Cross-site Scripting vulnerability in Exclusiveaddons Exclusive Addons for Elementor
The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘exad_infobox_animating_mask_style’ parameter in all versions up to, and including, 2.6.9.2 due to insufficient input sanitization and output escaping.
network
low complexity
exclusiveaddons CWE-79
5.4
2024-05-02 CVE-2024-2790 Cross-site Scripting vulnerability in Hasthemes HT Mega
The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Accordion widget in all versions up to, and including, 2.4.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
hasthemes CWE-79
5.4
2024-05-02 CVE-2024-2867 Cross-site Scripting vulnerability in Properfraction Profilepress
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 4.15.4 due to insufficient input sanitization and output escaping.
network
low complexity
properfraction CWE-79
5.4
2024-05-02 CVE-2024-2958 Cross-site Scripting vulnerability in Svs-Websoft SVS Pricing Tables
The SVS Pricing Tables plugin for WordPress is vulnerable to Stored Cross-Site Scripting via pricing table settings in all versions up to, and including, 1.0.4 due to insufficient input sanitization and output escaping.
network
low complexity
svs-websoft CWE-79
4.8
2024-05-02 CVE-2024-3045 Cross-site Scripting vulnerability in Wpovernight Woocommerce PDF Invoices& Packing Slips
The PDF Invoices & Packing Slips for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several parameters in versions up to, and including, 3.8.0 due to insufficient input sanitization and output escaping.
network
low complexity
wpovernight CWE-79
6.1
2024-05-02 CVE-2024-3161 Cross-site Scripting vulnerability in Jegtheme JEG Elementor KIT
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the countdown widget's attributes in all versions up to, and including, 2.6.4 due to insufficient input sanitization and output escaping.
network
low complexity
jegtheme CWE-79
5.4