Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-07-02 CVE-2024-5544 Cross-site Scripting vulnerability in Davidlingren Media Library Assistant
The Media Library Assistant plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the order parameter in all versions up to, and including, 3.17 due to insufficient input sanitization and output escaping.
network
low complexity
davidlingren CWE-79
6.1
2024-07-02 CVE-2024-5545 Missing Authorization vulnerability in Stylemixthemes Motors - CAR Dealer, Classifieds & Listing
The Motors – Car Dealer, Classifieds & Listing plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the stm_edit_delete_user_car function in all versions up to, and including, 1.4.8.
network
low complexity
stylemixthemes CWE-862
5.3
2024-07-02 CVE-2024-0158 Improper Input Validation vulnerability in Dell products
Dell BIOS contains an improper input validation vulnerability.
local
low complexity
dell CWE-20
6.7
2024-07-02 CVE-2024-32854 Unspecified vulnerability in Dell Powerscale Onefs
Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability.
local
low complexity
dell
6.7
2024-07-02 CVE-2024-5219 Cross-site Scripting vulnerability in Supsystic Easy Google Maps
The Easy Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's file upload feature in all versions up to, and including, 1.11.15 due to insufficient input sanitization and output escaping.
network
low complexity
supsystic CWE-79
5.4
2024-07-02 CVE-2024-1427 Cross-site Scripting vulnerability in Radiustheme the Post Grid
The The Post Grid – Shortcode, Gutenberg Blocks and Elementor Addon for Post Grid plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the section title tag attribute in all versions up to, and including, 7.7.1 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
radiustheme CWE-79
5.4
2024-07-02 CVE-2024-3999 Cross-site Scripting vulnerability in Spider-Themes Eazydocs
The EazyDocs WordPress plugin before 2.5.0 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
network
low complexity
spider-themes CWE-79
4.8
2024-07-02 CVE-2024-4627 Cross-site Scripting vulnerability in Rankmath SEO
The Rank Math SEO WordPress plugin before 1.0.219 does not sanitise and escape some of its settings, which could allow users with access to the General Settings (by default admin, however such access can be given to lower roles via the Role Manager feature of the Rank Math SEO WordPress plugin before 1.0.219) to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
network
low complexity
rankmath CWE-79
5.4
2024-07-02 CVE-2024-5419 Cross-site Scripting vulnerability in Voidcoders Void Contact Form 7 Widget for Elementor Page Builder
The Void Contact Form 7 Widget For Elementor Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'cf7_redirect_page' attribute within the plugin's Void Contact From 7 widget in all versions up to, and including, 2.4 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
voidcoders CWE-79
5.4
2024-07-02 CVE-2024-5938 Cross-site Scripting vulnerability in Boot Store Project Boot Store
The Boot Store theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘link’ parameter within the theme's Button shortcode in all versions up to, and including, 1.6.4 due to insufficient input sanitization and output escaping.
network
low complexity
boot-store-project CWE-79
5.4