CVE-2024-8286 |
Description: The webtoffee-gdpr-cookie-consent WordPress plugin before 2.6.1 does not have CSRF checks in some bulk actions, which could allow attackers to make logged in admins perform unwanted actions, such as deleting visit logs via CSRF attacks
CVSS: MEDIUM (6.5) EPSS Score: 0.01%
May 15th, 2025 (about 1 month ago)
|
CVE-2024-8284 |
Description: The Download Manager WordPress plugin before 3.2.99 does not sanitise and escape some of its settings, which could allow high privilege users such as editors to perform Cross-Site Scripting attacks even when unfiltered_html is disallowed
CVSS: MEDIUM (4.8) EPSS Score: 0.02%
May 15th, 2025 (about 1 month ago)
|
CVE-2024-8245 |
Description: The GamiPress WordPress plugin before 1.0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
May 15th, 2025 (about 1 month ago)
|
CVE-2024-8187 |
Description: The Smart Post Show WordPress plugin before 3.0.1 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
EPSS Score: 0.01%
May 15th, 2025 (about 1 month ago)
|
CVE-2024-8095 |
Description: The BabelZ WordPress plugin through 1.1.5 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
CVSS: MEDIUM (6.1) EPSS Score: 0.03%
May 15th, 2025 (about 1 month ago)
|
CVE-2024-8094 |
Description: The Ntz Antispam WordPress plugin through 2.0e does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS: MEDIUM (6.5) EPSS Score: 0.01%
May 15th, 2025 (about 1 month ago)
|
CVE-2024-8090 |
Description: The JavaScript Logic WordPress plugin through 0.1 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
EPSS Score: 0.01%
May 15th, 2025 (about 1 month ago)
|
CVE-2024-8085 |
Description: The PeoplePond WordPress plugin through 1.1.9 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
EPSS Score: 0.01%
May 15th, 2025 (about 1 month ago)
|
CVE-2024-8082 |
Description: The Widgets Reset WordPress plugin through 0.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS: MEDIUM (4.3) EPSS Score: 0.02%
May 15th, 2025 (about 1 month ago)
|
CVE-2024-8050 |
Description: The Custom Author Base WordPress plugin through 1.1.1 does not have CSRF check in place when updating its settings, which could allow attackers to make a logged in admin change them via a CSRF attack
CVSS: MEDIUM (4.3) EPSS Score: 0.01%
May 15th, 2025 (about 1 month ago)
|