In Download Manager plugin for WordPress versions 3.3.03 and prior a medium severity vulnerability CVE-2024-11768 was detected. This vulnerability allows attackers to download password-protected files due to improper password validation. To address this issue, users should upgrade to version 3.3.04 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11768.
Read more CMSIn the Avada (Fusion) Builder plugin for WordPress versions up to 3.11.12 a medium severity vulnerability CVE-2024-12335 was detected. This vulnerability allows attackers with contributor-level access or higher to access sensitive information from protected, private, or draft posts in WordPress. To fix this issue, users should upgrade Avada (Fusion) Builder plugin for WordPress to version 3.11.13. For more details, visit https://nvd.nist.gov/vuln/detail/cve-2024-12335.
Read more CMSIn WPForms WordPress plugin versions prior to 1.9.2.3 a medium severity vulnerability CVE-2024-11223 was detected. This vulnerability allows high-privilege users, such as administrators, to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disabled (e.g., in multisite setups). To address this issue, users should upgrade to version 1.9.2.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11223.
Read more CMSIn WooCommerce Point of Sale plugin for WordPress versions up to 6.1.0 a critical severity vulnerability CVE-2024-11281 was detected. This vulnerability allows attackers to change the email and reset the password of any user, including administrators, due to insufficient validation of the ‘logged_in_user_id’ value. To address this issue, users should upgrade to version 6.2.0 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-11281.
Read more E-commerceIn Broken Link Checker WordPress plugin versions prior to 2.4.2 a high severity vulnerability CVE-2024-10903 was detected. This vulnerability allows admin users to perform Server-Side Request Forgery (SSRF) attacks by exploiting unvalidated link URLs, potentially compromising multisite installations. To address this issue, users should upgrade to version 2.4.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10903.
Read more CMSIn WordPress Simple Shopping Cart plugin versions 5.0.7 and prior a medium severity vulnerability CVE-2024-12622 was detected. This vulnerability lets users with contributor-level access or higher add harmful scripts through the ‘wp_cart_button’ and ‘wp_cart_display_product’ shortcodes. No patched version has been officially released at this time. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12622.
Read more CMSIn Tracking Code Manager plugin versions 2.3.0 and prior a medium severity vulnerability CVE-2024-8721 was detected. This vulnerability allows users with Contributor-level access or higher add harmful scripts through the tracking code field, which will execute whenever a user accesses an injected page. No patched version has been officially released at this time. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-8721.
Read more CMSIn WP Datepicker plugin versions 2.1.4 and prior a medium severity vulnerability CVE-2024-12468 was detected. This vulnerability allows unauthenticated attackers to inject arbitrary web scripts via the ‘wpdp_get_selected_datepicker’ parameter, which execute if they successfully trick a user into performing an action such as clicking on a link. No patched version has been officially released at this time. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-12468.
Read more CMSIn Download Manager WordPress plugin versions before 3.3.03 a medium severity vulnerability CVE-2024-10706 was detected. This vulnerability allows attackers to perform Stored Cross-Site Scripting attacks, even when the unfiltered_html capability is disallowed (for example in multisite setups). To address this issue, users should upgrade Download Manager plugin to version 3.3.03 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2024-10706.
Read more CMS