Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-04-09 CVE-2024-0826 Cross-site Scripting vulnerability in Qodeinteractive QI Addons for Elementor
The Qi Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 1.6.7 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
qodeinteractive CWE-79
5.4
2024-04-09 CVE-2024-1412 Cross-site Scripting vulnerability in Caseproof Memberpress
The Memberpress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘message’ and 'error' parameters in all versions up to, and including, 1.11.26 due to insufficient input sanitization and output escaping.
network
low complexity
caseproof CWE-79
6.1
2024-04-09 CVE-2024-1458 Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘text_alignment’ attribute of the Animated Text widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping.
network
low complexity
livemeshelementor CWE-79
5.4
2024-04-09 CVE-2024-1461 Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attribute of the Team Members widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping.
network
low complexity
livemeshelementor CWE-79
5.4
2024-04-09 CVE-2024-1463 Cross-site Scripting vulnerability in Thimpress Learnpress
The LearnPress – WordPress LMS Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Course, Lesson, and Quiz title and content in all versions up to, and including, 4.2.6.3 due to insufficient input sanitization and output escaping.
network
low complexity
thimpress CWE-79
4.8
2024-04-09 CVE-2024-1464 Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘style’ attribute of the Posts Slider widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping.
network
low complexity
livemeshelementor CWE-79
5.4
2024-04-09 CVE-2024-1465 Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘carousel_skin’ attribute of the Posts Carousel widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping.
network
low complexity
livemeshelementor CWE-79
5.4
2024-04-09 CVE-2024-1466 Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘slider_style’ attribute of the Posts Multislider widget in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping.
network
low complexity
livemeshelementor CWE-79
5.4
2024-04-09 CVE-2024-1498 Cross-site Scripting vulnerability in Leevio Happy Addons for Elementor
The Happy Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Photo Stack Widget in all versions up to, and including, 3.10.3 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
leevio CWE-79
5.4
2024-04-09 CVE-2024-1794 Cross-site Scripting vulnerability in Incsub Forminator
The Forminator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g.
network
low complexity
incsub CWE-79
6.1