CVE-2024-8542 |
Description: The Everest Forms WordPress plugin before 3.0.3.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVSS: MEDIUM (4.8) EPSS Score: 0.02%
May 15th, 2025 (24 days ago)
|
CVE-2024-8493 |
Description: The Events Calendar WordPress plugin before 6.6.4 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
CVSS: MEDIUM (4.8) EPSS Score: 0.02%
May 15th, 2025 (24 days ago)
|
CVE-2024-8492 |
Description: The Hustle WordPress plugin through 7.8.5 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVSS: MEDIUM (4.8) EPSS Score: 0.02%
May 15th, 2025 (24 days ago)
|
CVE-2024-8426 |
Description: The Page Builder: Pagelayer WordPress plugin before 1.8.8 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVSS: MEDIUM (4.8) EPSS Score: 0.03%
May 15th, 2025 (24 days ago)
|
CVE-2024-8398 |
Description: The Simple Nav Archives WordPress plugin through 2.1.3 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS: MEDIUM (4.3) EPSS Score: 0.03%
May 15th, 2025 (24 days ago)
|
CVE-2024-8286 |
Description: The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks
CVSS: MEDIUM (6.5) EPSS Score: 0.03%
May 15th, 2025 (24 days ago)
|
CVE-2024-8284 |
Description: The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVSS: MEDIUM (4.8) EPSS Score: 0.02%
May 15th, 2025 (24 days ago)
|
CVE-2024-8245 |
Description: The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS: MEDIUM (4.3) EPSS Score: 0.03%
May 15th, 2025 (24 days ago)
|
CVE-2024-8095 |
Description: The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVSS: MEDIUM (6.1) EPSS Score: 0.03%
May 15th, 2025 (24 days ago)
|
CVE-2024-8094 |
Description: The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS: MEDIUM (6.5) EPSS Score: 0.01%
May 15th, 2025 (24 days ago)
|