Vulnerabilities > Kraftplugins

DATE CVE VULNERABILITY TITLE RISK
2024-11-01 CVE-2024-47311 Missing Authorization vulnerability in Kraftplugins Wheel of Life
Missing Authorization vulnerability in Kraft Plugins Wheel of Life allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Wheel of Life: from n/a through 1.1.8.
network
low complexity
kraftplugins CWE-862
critical
9.8
2024-10-24 CVE-2024-49693 Cross-site Scripting vulnerability in Kraftplugins Mega Elements
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements allows Stored XSS.This issue affects Mega Elements: from n/a through 1.2.6.
network
low complexity
kraftplugins CWE-79
5.4
2024-10-02 CVE-2024-9172 Cross-site Scripting vulnerability in Kraftplugins Demo Importer Plus
The Demo Importer Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 2.0.1 due to insufficient input sanitization and output escaping.
network
low complexity
kraftplugins CWE-79
5.4
2024-07-21 CVE-2024-37466 Cross-site Scripting vulnerability in Kraftplugins Mega Elements
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Kraftplugins Mega Elements.This issue affects Mega Elements: from n/a through 1.2.2.
network
low complexity
kraftplugins CWE-79
5.4
2024-06-20 CVE-2024-3627 Missing Authorization vulnerability in Kraftplugins Wheel of Life
The Wheel of Life: Coaching and Assessment Tool for Life Coach plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on several functions in the AjaxFunctions.php file in all versions up to, and including, 1.1.7.
network
low complexity
kraftplugins CWE-862
5.4