Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2024-06-15 CVE-2024-4095 The Collapse-O-Matic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'expand' and 'expandsub' shortcode in all versions up to, and including, 1.8.5.7 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
6.4
2024-06-15 CVE-2024-5858 The AI Infographic Maker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the qcld_openai_title_generate_desc AJAX action in all versions up to, and including, 4.7.4.
network
low complexity
4.3
2024-06-15 CVE-2024-5868 The WooCommerce - Social Login plugin for WordPress is vulnerable to Email Verification in all versions up to, and including, 2.6.2 via the use of insufficiently random activation code.
network
low complexity
6.5
2024-06-15 CVE-2024-2544 Missing Authorization vulnerability in Sygnoos Popup Builder
The Popup Builder plugin for WordPress is vulnerable to unauthorized modification of data and loss of data due to a missing capability check on all AJAX actions.
network
low complexity
sygnoos CWE-862
6.4
2024-06-15 CVE-2024-3814 Cross-site Scripting vulnerability in Tagdiv Composer 4.2/4.4
The tagDiv Composer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'single' module in all versions up to, and including, 4.8 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
tagdiv CWE-79
4.8
2024-06-15 CVE-2024-3815 Cross-site Scripting vulnerability in Tagdiv Newspaper
The Newspaper theme for WordPress is vulnerable to Stored Cross-Site Scripting via attachment meta in the archive page in all versions up to, and including, 12.6.5 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
tagdiv CWE-79
4.8
2024-06-15 CVE-2024-4479 Cross-site Scripting vulnerability in Jegtheme JEG Elementor KIT
The Jeg Elementor Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the sg_general_toggle_tab_enable and sg_accordion_style attributes within the plugin's JKit - Tabs and JKit - Accordion widget, respectively, in all versions up to, and including, 2.6.5 due to insufficient input sanitization and output escaping.
network
low complexity
jegtheme CWE-79
5.4
2024-06-15 CVE-2024-5263 Cross-site Scripting vulnerability in Wpmet Elementskit
The ElementsKit Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Motion Text and Table widgets in all versions up to, and including, 3.6.2 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wpmet CWE-79
5.4
2024-06-14 CVE-2024-37889 Authorization Bypass Through User-Controlled Key vulnerability in Treyww Myfinances
MyFinances is a web application for managing finances.
network
low complexity
treyww CWE-639
6.5
2024-06-14 CVE-2024-36599 Cross-site Scripting vulnerability in Aegon Life Insurance Management System 1.0
A cross-site scripting (XSS) vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the name parameter at insertClient.php.
network
low complexity
aegon CWE-79
6.1