Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-08-20 CVE-2024-42335 Cross-site Scripting vulnerability in 7-Twenty BOT
7Twenty - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
network
low complexity
7-twenty CWE-79
5.4
2024-08-20 CVE-2024-41697 Cross-site Scripting vulnerability in Priority-Software Priority 19.1.0.68/22.0
Priority - CWE-80: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
network
low complexity
priority-software CWE-79
6.1
2024-08-20 CVE-2024-7054 The Popup Maker – Boost Sales, Conversions, Optins, Subscribers with the Ultimate WP Popups Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘close_text’ parameter in all versions up to, and including, 1.19.0 due to insufficient input sanitization and output escaping.
network
low complexity
6.4
2024-08-20 CVE-2024-5576 The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'course_carousel_skin' attribute within the plugin's Course Carousel widget in all versions up to, and including, 2.1.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
6.4
2024-08-20 CVE-2024-6864 Cross-site Scripting vulnerability in Sayandatta WP Last Modified Info
The WP Last Modified Info plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘template’ attribute of the lmt-post-modified-info shortcode in all versions up to, and including, 1.9.0 due to insufficient input sanitization and output escaping.
network
low complexity
sayandatta CWE-79
5.4
2024-08-20 CVE-2024-5763 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the video_date attribute within the plugin's Video widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and output escaping.
network
low complexity
posimyth CWE-79
5.4
2024-08-20 CVE-2024-6575 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘res_width_value’ parameter within the plugin's tp_page_scroll widget in all versions up to, and including, 5.6.2 due to insufficient input sanitization and output escaping.
network
low complexity
posimyth CWE-79
5.4
2024-08-20 CVE-2024-7775 Cross-site Scripting vulnerability in Bitapps Contact Form Builder
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing input validation in the addCustomCode function in versions 2.0 to 2.13.9.
network
low complexity
bitapps CWE-79
4.8
2024-08-20 CVE-2024-7782 Path Traversal vulnerability in Bitapps Contact Form Builder
The Contact Form by Bit Form: Multi Step Form, Calculation Contact Form, Payment Contact Form & Custom Contact Form builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the iconRemove function in versions 2.0 to 2.13.4.
network
low complexity
bitapps CWE-22
6.5
2024-08-20 CVE-2024-5939 Missing Authorization vulnerability in Givewp
The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'setup_wizard' function in all versions up to, and including, 3.13.0.
network
low complexity
givewp CWE-862
5.3