Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2025-02-01 CVE-2024-13612 Cross-site Scripting vulnerability in Wordplus Better Messages
The Better Messages – Live Chat for WordPress, BuddyPress, PeepSo, Ultimate Member, BuddyBoss plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'better_messages_live_chat_button' shortcode in all versions up to, and including, 2.6.9 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
wordplus CWE-79
5.4
2025-02-01 CVE-2024-13775 Missing Authorization vulnerability in Vanquish Woocommerce Support Ticket System
The WooCommerce Support Ticket System plugin for WordPress is vulnerable to unauthorized access and loss of data due to missing capability checks on the 'ajax_delete_message', 'ajax_get_customers_partial_list', and 'ajax_get_admins_list' functions in all versions up to, and including, 17.8.
network
low complexity
vanquish CWE-862
5.4
2025-02-01 CVE-2024-12825 Missing Authorization vulnerability in Brechtvds Custom Related Posts
The Custom Related Posts plugin for WordPress is vulnerable to unauthorized access & modification of data due to a missing capability check on three AJAX actions in all versions up to, and including, 1.7.3.
network
low complexity
brechtvds CWE-862
5.4
2025-02-01 CVE-2024-13371 Missing Authorization vulnerability in Wpjobportal WP JOB Portal
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to unauthorized arbitrary emails sending due to a missing capability check on the sendEmailToJobSeeker() function in all versions up to, and including, 2.2.6.
network
low complexity
wpjobportal CWE-862
5.3
2025-02-01 CVE-2024-13372 Authorization Bypass Through User-Controlled Key vulnerability in Wpjobportal WP JOB Portal
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the getresumefiledownloadbyid() and getallresumefiles() functions due to missing validation on a user controlled key.
network
low complexity
wpjobportal CWE-639
5.3
2025-02-01 CVE-2024-13425 Authorization Bypass Through User-Controlled Key vulnerability in Wpjobportal WP JOB Portal
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the enforcedelete() function due to missing validation on a user controlled key.
network
low complexity
wpjobportal CWE-639
4.3
2025-02-01 CVE-2024-13428 Authorization Bypass Through User-Controlled Key vulnerability in Wpjobportal WP JOB Portal
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the deleteCompanyLogo() due to missing validation on a user controlled key.
network
low complexity
wpjobportal CWE-639
5.3
2025-02-01 CVE-2024-13429 Authorization Bypass Through User-Controlled Key vulnerability in Wpjobportal WP JOB Portal
The WP Job Portal – A Complete Recruitment System for Company or Job Board website plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.2.6 via the 'jobenforcedelete' due to missing validation on a user controlled key.
network
low complexity
wpjobportal CWE-639
4.3
2025-02-01 CVE-2024-11829 Cross-site Scripting vulnerability in Posimyth the Plus Addons for Elementor
The The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table Widget's searchable_label parameter in all versions up to, and including, 6.1.8 due to insufficient input sanitization and output escaping.
network
low complexity
posimyth CWE-79
5.4
2025-02-01 CVE-2024-13341 SQL Injection vulnerability in Techspawn Multiloca
The MultiLoca - WooCommerce Multi Locations Inventory Management plugin for WordPress is vulnerable to SQL Injection via the 'data-id' parameter in all versions up to, and including, 4.1.11 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.
network
low complexity
techspawn CWE-89
6.5