Vulnerabilities > Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-8546 Cross-site Scripting vulnerability in Wpmet Elementskit Elementor Addons
The ElementsKit Elementor addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video widget in all versions up to, and including, 3.2.7 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpmet CWE-79
5.4
2024-09-25 CVE-2024-8858 Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping.
network
low complexity
livemeshelementor CWE-79
5.4
2024-09-25 CVE-2024-9169 The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping.
network
low complexity
CWE-79
5.5
2024-09-25 CVE-2024-47303 Cross-site Scripting vulnerability in Livemeshelementor Addons for Elementor
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Livemesh Livemesh Addons for Elementor allows Stored XSS.This issue affects Livemesh Addons for Elementor: from n/a through 8.5.
network
low complexity
livemeshelementor CWE-79
5.4
2024-09-25 CVE-2024-3866 Cross-site Scripting vulnerability in Ninjaforms Ninja Forms
The Ninja Forms Contact Form plugin for WordPress is vulnerable to Reflected Self-Based Cross-Site Scripting via the 'Referer' header in all versions up to, and including, 3.8.15 due to insufficient input sanitization and output escaping.
network
low complexity
ninjaforms CWE-79
6.1
2024-09-25 CVE-2024-7878 Cross-site Scripting vulnerability in Technowich WP Ulike
The WP ULike WordPress plugin before 4.7.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
technowich CWE-79
4.8
2024-09-25 CVE-2024-8668 Cross-site Scripting vulnerability in Hasthemes Woolentor - Woocommerce Elementor Addons + Builder
The ShopLentor – WooCommerce Builder for Elementor & Gutenberg +12 Modules – All in One Solution (formerly WooLentor) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the tooltip and countdown functionality in all versions up to, and including, 2.9.7 due to insufficient input sanitization and output escaping.
network
low complexity
hasthemes CWE-79
5.4
2024-09-25 CVE-2024-8515 Cross-site Scripting vulnerability in Themesflat Addons for Elementor 2.0.0/2.1.2
The Themesflat Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via several widgets like 'TF E Slider Widget', 'TF Video Widget', 'TF Team Widget' and more in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping on URL attributes.
network
low complexity
themesflat CWE-79
5.4
2024-09-25 CVE-2024-7617 Cross-site Scripting vulnerability in Itpathsolutions Contact Form to ANY API
The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Contact Form 7 form fields in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping.
network
low complexity
itpathsolutions CWE-79
6.1
2024-09-25 CVE-2024-8549 Cross-site Scripting vulnerability in Xtendify Simple Calendar
The Simple Calendar – Google Calendar Plugin plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.4.2.
network
low complexity
xtendify CWE-79
6.1