Ocean Extra Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-3167 | WordPress Plugin Vulnerability Report

Plugin Name: Ocean Extra Key Information: Software Type: Plugin Software Slug: ocean-extra Software Status: Active Software Author: oceanwp Software Downloads: 20,664,296 Active Installs: 700,000 Last Updated: April 16, 2024 Patched Versions: 2.2.7 Affected Versions: <= 2.2.6 Vulnerability Details: Name: Ocean Extra <= 2.2.6 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-3167 CVSS Score:…

Read More

RSS Aggregator by Feedzy Vulnerability – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator – Authenticated Stored Cross-Site Scripting via Shortcode Error Message – CVE-2023-6877 | WordPress Plugin Vulnerability Report 

WP Plugin Vulnerabilities Image - RSS Aggregator by Feedzy Vulnerability – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator - Authenticated Stored Cross-Site Scripting via Shortcode Error Message - CVE-2023-6877 | WordPress Plugin Vulnerability Report  - Security

Plugin Name: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Key Information: Software Type: Plugin Software Slug: feedzy-rss-feeds Software Status: Active Software Author: themeisle Software Downloads: 2,215,056 Active Installs: 50,000 Last Updated: April 16, 2024 Patched Versions: 4.3.4 Affected Versions: <= 4.3.3 Vulnerability Details: Name: RSS Aggregator by…

Read More

Sydney Toolbox Vulnerability – Authenticated Stored Cross-Site Scripting via Filterable Gallery – CVE-2024-3208 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Sydney Toolbox Vulnerability - Authenticated Stored Cross-Site Scripting via Filterable Gallery - CVE-2024-3208 | WordPress Plugin Vulnerability Report - Security

Plugin Name: Sydney Toolbox Key Information: Software Type: Plugin Software Slug: sydney-toolbox Software Status: Active Software Author: athemes Software Downloads: 2,211,650 Active Installs: 80,000 Last Updated: April 8, 2024 Patched Versions: 1.29 Affected Versions: <= 1.28 Vulnerability Details: Name: Sydney Toolbox <= 1.28 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Filterable Gallery Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE:…

Read More

WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Vulnerability – Missing Authorization to Unauthenticated Settings Reset – CVE-2024-3216 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Vulnerability - Missing Authorization to Unauthenticated Settings Reset - CVE-2024-3216 | WordPress Plugin Vulnerability Report - Security

Plugin Name: WooCommerce PDF Invoices, Packing Slips, Delivery Notes and Shipping Labels Key Information: Software Type: Plugin Software Slug: print-invoices-packing-slip-labels-for-woocommerce Software Status: Active Software Author: webtoffee Software Downloads: 1,383,697 Active Installs: 50,000 Last Updated: April 8, 2024 Patched Versions: 4.4.3 Affected Versions: <= 4.4.2 Vulnerability Details: Name: WooCommerce PDF Invoices, Packing Slips, Delivery Notes and…

Read More

EmbedPress Vulnerability – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-3244 & CVE-2024-3245 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - EmbedPress Vulnerability – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor - Authenticated (Contributor+) Stored Cross-Site Scripting - CVE-2024-3244 & CVE-2024-3245 | WordPress Plugin Vulnerability Report - Security

Plugin Name: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor Key Information: Software Type: Plugin Software Slug: embedpress Software Status: Active Software Author: wpdevteam Software Downloads: 2,444,164 Active Installs: 90,000 Last Updated: April 10, 2024 Patched Versions: 3.9.15 Affected Versions: <= 3.9.14…

Read More

FancyBox for WordPress Vulnerability – Authenticated (Admin+) Stored Cross-Site Scripting – CVE-2024-0662 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - FancyBox for WordPress Vulnerability - Authenticated (Admin+) Stored Cross-Site Scripting - CVE-2024-0662 | WordPress Plugin Vulnerability Report - Security

Plugin Name: FancyBox for WordPress Key Information: Software Type: Plugin Software Slug: fancybox-for-wordpress Software Status: Active Software Author: colorlibplugins Software Downloads: 1,832,612 Active Installs: 50,000 Last Updated: April 10, 2024 Patched Versions: 3.3.4 Affected Versions: 3.0.2 – 3.3.3 Vulnerability Details: Name: FancyBox for WordPress 3.0.2 – 3.3.3 Title: Authenticated (Admin+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N…

Read More

Image Watermark Vulnerability – Missing Authorization to Authenticated (Subscriber+) Watermark Modification – CVE-2024-1994 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Image Watermark Vulnerability - Missing Authorization to Authenticated (Subscriber+) Watermark Modification - CVE-2024-1994 | WordPress Plugin Vulnerability Report - Security

Plugin Name: Image Watermark Key Information: Software Type: Plugin Software Slug: image-watermark Software Status: Active Software Author: dfactory Software Downloads: 842,453 Active Installs: 50,000 Last Updated: April 10, 2024 Patched Versions: 1.7.4 Affected Versions: <= 1.7.3 Vulnerability Details: Name: Image Watermark <= 1.7.3 Title: Missing Authorization to Authenticated (Subscriber+) Watermark Modification Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVE: CVE-2024-1994…

Read More

Photo Gallery by 10Web Vulnerability – Mobile-Friendly Image Gallery – Authenticated (Admin+) Stored Cross-Site Scripting via SVG – CVE-2024-2296 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Photo Gallery by 10Web Vulnerability – Mobile-Friendly Image Gallery - Authenticated (Admin+) Stored Cross-Site Scripting via SVG - CVE-2024-2296 | WordPress Plugin Vulnerability Report - Security

Plugin Name: Photo Gallery by 10Web – Mobile-Friendly Image Gallery Key Information: Software Type: Plugin Software Slug: photo-gallery Software Status: Active Software Author: 10web Software Downloads: 17,757,662 Active Installs: 200,000 Last Updated: April 10, 2024 Patched Versions: 1.8.22 Affected Versions: <= 1.8.21 Vulnerability Details: Name: Photo Gallery by 10Web – Mobile-Friendly Image Gallery <= 1.8.21…

Read More

Carousel, Slider, Gallery by WP Carousel Vulnerability – Authenticated Stored Cross-Site Scripting – CVE-2024-2949 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Carousel, Slider, Gallery by WP Carousel Vulnerability – Authenticated Stored Cross-Site Scripting - CVE-2024-2949 | WordPress Plugin Vulnerability Report - Security

Plugin Name: Carousel, Slider, Gallery by WP Carousel – Image Carousel & Photo Gallery, Post Carousel & Post Grid, Product Carousel & Product Grid for WooCommerce Key Information: Software Type: Plugin Software Slug: wp-carousel-free Software Status: Active Software Author: shapedplugin Software Downloads: 1,321,112 Active Installs: 60,000 Last Updated: April 15, 2024 Patched Versions: 2.6.4 Affected…

Read More

Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Vulnerability – Authenticated Stored Cross-Site Scripting – CVE-2024-1428 & CVE-2024-0837 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Vulnerability - Authenticated Stored Cross-Site Scripting - CVE-2024-1428 & CVE-2024-0837 | WordPress Plugin Vulnerability Report - Security

Plugin Name: Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) Key Information: Software Type: Plugin Software Slug: bdthemes-element-pack-lite Software Status: Active Software Author: bdthemes Software Downloads: 1,990,743 Active Installs: 100,000 Last Updated: April 15, 2024 Patched Versions: 5.5.4 Affected Versions: <= 5.5.3 Vulnerability Details: Name: Element Pack Elementor Addons…

Read More