Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-02-05 CVE-2024-0448 Cross-site Scripting vulnerability in Livemesh Elementor Addons
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget URL parameters in all versions up to, and including, 8.3.1 due to insufficient input sanitization and output escaping.
network
low complexity
livemesh CWE-79
5.4
2024-02-05 CVE-2024-0508 Cross-site Scripting vulnerability in Themeisle Orbit FOX
The Orbit Fox by ThemeIsle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Pricing Table Elementor Widget in all versions up to, and including, 2.10.27 due to insufficient input sanitization and output escaping on the user supplied link URL.
network
low complexity
themeisle CWE-79
5.4
2024-02-05 CVE-2024-0509 Cross-site Scripting vulnerability in HWK WP 404 Auto Redirect to Similar Post
The WP 404 Auto Redirect to Similar Post plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘request’ parameter in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping.
network
low complexity
hwk CWE-79
6.1
2024-02-05 CVE-2024-0585 Cross-site Scripting vulnerability in Wpdeveloper Essential Addons for Elementor
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Filterable Gallery widget in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the Image URL.
network
low complexity
wpdeveloper CWE-79
5.4
2024-02-05 CVE-2024-0586 Cross-site Scripting vulnerability in Wpdeveloper Essential Addons for Elementor
The Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Login/Register Element in all versions up to, and including, 5.9.4 due to insufficient input sanitization and output escaping on the custom login URL.
network
low complexity
wpdeveloper CWE-79
5.4
2024-02-05 CVE-2024-0597 Cross-site Scripting vulnerability in Squirrly SEO Plugin BY Squirrly SEO
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 12.3.15 due to insufficient input sanitization and output escaping.
network
low complexity
squirrly CWE-79
4.8
2024-02-05 CVE-2024-0612 Cross-site Scripting vulnerability in Contentviewspro Content Views
The Content Views – Post Grid, Slider, Accordion (Gutenberg Blocks and Shortcode) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping.
network
low complexity
contentviewspro CWE-79
4.8
2024-02-05 CVE-2024-0630 Cross-site Scripting vulnerability in Wprssaggregator WP RSS Aggregator
The WP RSS Aggregator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the RSS feed source in all versions up to, and including, 4.23.4 due to insufficient input sanitization and output escaping.
network
low complexity
wprssaggregator CWE-79
4.8
2024-02-05 CVE-2024-0659 Cross-site Scripting vulnerability in Awesomemotive Easy Digital Downloads
The Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the variable pricing option title in all versions up to, and including, 3.2.6 due to insufficient input sanitization and output escaping.
network
low complexity
awesomemotive CWE-79
4.8
2024-02-05 CVE-2024-0678 Cross-site Scripting vulnerability in Tychesoftwares Order Delivery Date for WP E-Commerce 1.2
The Order Delivery Date for WP e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'available-days-tf' parameter in all versions up to, and including, 1.2 due to insufficient input sanitization and output escaping.
network
low complexity
tychesoftwares CWE-79
6.1