Vulnerabilities > Kraftplugins

DATE CVE VULNERABILITY TITLE RISK
2024-07-21 CVE-2024-37466 Cross-site Scripting vulnerability in Kraftplugins Mega Elements
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements.This issue affects Mega Elements: from n/a through 1.2.2.
network
low complexity
kraftplugins CWE-79
5.4
2024-06-20 CVE-2024-3627 Missing Authorization vulnerability in Kraftplugins Wheel of Life
The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the AjaxFunctions.php file in all versions up to, and including, 1.1.7.
network
low complexity
kraftplugins CWE-862
5.4