Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-24 CVE-2024-6629 Cross-site Scripting vulnerability in Plugins360 All-In-One Video Gallery
The All-in-One Video Gallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Video shortcode in all versions up to, and including, 3.7.1 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
plugins360 CWE-79
5.4
2024-07-24 CVE-2024-6094 Cross-site Scripting vulnerability in Technowich WP Ulike
The WP ULike WordPress plugin before 4.7.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
technowich CWE-79
4.8
2024-07-24 CVE-2024-6836 Missing Authorization vulnerability in Funnelkit Funnel Builder
The Funnel Builder for WordPress by FunnelKit – Customize WooCommerce Checkout Pages, Create Sales Funnels, Order Bumps & One Click Upsells plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on multiple functions in all versions up to, and including, 3.4.6.
network
low complexity
funnelkit CWE-862
4.3
2024-07-24 CVE-2024-40767 Unspecified vulnerability in Openstack Nova
In OpenStack Nova before 27.4.1, 28 before 28.2.1, and 29 before 29.1.1, by supplying a raw format image that is actually a crafted QCOW2 image with a backing file path or VMDK flat image with a descriptor file path, an authenticated user may convince systems to return a copy of the referenced file's contents from the server, resulting in unauthorized access to potentially sensitive data.
network
low complexity
openstack
6.5
2024-07-24 CVE-2024-3246 Cross-Site Request Forgery (CSRF) vulnerability in Litespeedtech Litespeed Cache
The LiteSpeed Cache plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.2.0.1.
network
low complexity
litespeedtech CWE-352
5.4
2024-07-24 CVE-2024-5861 Missing Authorization vulnerability in Wpeasypay WP Easypay
The WP EasyPay – Square for WordPress plugin for WordPress is vulnerable to unauthorized modification of datadue to a missing capability check on the wpep_square_disconnect() function in all versions up to, and including, 4.2.3.
network
low complexity
wpeasypay CWE-862
6.5
2024-07-24 CVE-2024-6751 Cross-Site Request Forgery (CSRF) vulnerability in Wpwebinfotech Social Auto Poster
The Social Auto Poster plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 5.3.14.
network
low complexity
wpwebinfotech CWE-352
6.5
2024-07-24 CVE-2024-6752 Cross-site Scripting vulnerability in Wpwebinfotech Social Auto Poster
The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘wp_name’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping.
network
low complexity
wpwebinfotech CWE-79
5.4
2024-07-24 CVE-2024-6753 Cross-site Scripting vulnerability in Wpwebinfotech Social Auto Poster
The Social Auto Poster plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘mapTypes’ parameter in the 'wpw_auto_poster_map_wordpress_post_type' AJAX function in all versions up to, and including, 5.3.14 due to insufficient input sanitization and output escaping.
network
low complexity
wpwebinfotech CWE-79
6.1
2024-07-24 CVE-2024-6754 Missing Authorization vulnerability in Wpwebinfotech Social Auto Poster
The Social Auto Poster plugin for WordPress is vulnerable to unauthorized modification of data to a missing capability check on the ‘wpw_auto_poster_update_tweet_template’ function in all versions up to, and including, 5.3.14.
network
low complexity
wpwebinfotech CWE-862
4.3