Event Tickets and Registration Vulnerability – Improper Authorization to Information Disclosure – CVE-2024-2261 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Event Tickets and Registration Vulnerability - Improper Authorization to Information Disclosure - CVE-2024-2261 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Event Tickets and Registration Key Information: Software Type: Plugin Software Slug: event-tickets Software Status: Active Software Author: theeventscalendar Software Downloads: 3,490,727 Active Installs: 80,000 Last Updated: March 27, 2024 Patched Versions: 5.8.3 Affected Versions: <= 5.8.2 Vulnerability Details: Name: Event Tickets and Registration <= 5.8.2 Title: Improper Authorization to Information Disclosure Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N…

Read More

Master Addons Vulnerability – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget – CVE-2024-2139 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Master Addons Vulnerability – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor - Authenticated (Contributor+) Stored Cross-Site Scripting via Pricing Table Widget - CVE-2024-2139 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Master Addons – Free Widgets, Hover Effects, Toggle, Conditions, Animations for Elementor Key Information: Software Type: Plugin Software Slug: master-addons Software Status: Active Software Author: litonice13 Software Downloads: 1,012,079 Active Installs: 40,000 Last Updated: March 26, 2024 Patched Versions: 2.0.5.7 Affected Versions: <= 2.0.5.6 Vulnerability Details: Name: Master Addons for Elementor <= 2.0.5.6…

Read More

Link Whisper Free Vulnerability- Authenticated (Contributor+) PHP Object Injection – CVE-2024-2693 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Link Whisper Free Vulnerability- Authenticated (Contributor+) PHP Object Injection - CVE-2024-2693 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Link Whisper Free Key Information: Software Type: Plugin Software Slug: link-whisper Software Status: Active Software Author: linkwhspr Software Downloads: 449,941 Active Installs: 30,000 Last Updated: March 26, 2024 Patched Versions: 0.7.2 Affected Versions: <= 0.7.1 Vulnerability Details: Name: Link Whisper Free <= 0.7.1 Authenticated (Contributor+) PHP Object Injection Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE: CVE-2024-2693 CVSS…

Read More

VK All in One Expansion Unit – Authenticated (Contributor+) Stored Cross-Site Scripting via className – CVE-2024-2170 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - VK All in One Expansion Unit - Authenticated (Contributor+) Stored Cross-Site Scripting via className - CVE-2024-2170 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: VK All in One Expansion Unit Key Information: Software Type: Plugin Software Slug: vk-all-in-one-expansion-unit Software Status: Active Software Author: kurudrive Software Downloads: 5,085,263 Active Installs: 100,000 Last Updated: March 25, 2024 Patched Versions: 9.97.0.0 Affected Versions: <= 9.96.0.1 Vulnerability Details: Name: VK All in One Expansion Unit <= 9.96.0.1 Title: Authenticated (Contributor+) Stored…

Read More

Check & Log Email Vulnerability – Unauthenticated Hook Injection – CVE-2024-0866 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Check & Log Email Vulnerability - Unauthenticated Hook Injection - CVE-2024-0866 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Check & Log Email Key Information: Software Type: Plugin Software Slug: check-email Software Status: Active Software Author: checkemail Software Downloads: 1,430,487 Active Installs: 100,000 Last Updated: March 25, 2024 Patched Versions: 1.0.10 Affected Versions: <= 1.0.9 Vulnerability Details: Name: Check & Log Email <= 1.0.9 Title: Unauthenticated Hook Injection Type: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H CVE: CVE-2024-0866…

Read More

Paid Memberships Pro Vulnerability– Content Restriction, User Registration, & Paid Subscriptions – Cross-Site Request Forgery – CVE-2024-0588 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Paid Memberships Pro Vulnerability– Content Restriction, User Registration, & Paid Subscriptions - Cross-Site Request Forgery - CVE-2024-0588 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions Key Information: Software Type: Plugin Software Slug: paid-memberships-pro Software Status: Active Software Author: strangerstudios Software Downloads: 5,653,134 Active Installs: 90,000 Last Updated: March 26, 2024 Patched Versions: 3.0 Affected Versions: <= 2.12.10 Vulnerability Details: Name: Paid Memberships Pro <= 2.12.10 Title: Cross-Site…

Read More

BetterDocs Vulnerability – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode – CVE-2024-2845 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - BetterDocs Vulnerability – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode - CVE-2024-2845 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: BetterDocs – Best Documentation, FAQ & Knowledge Base Plugin with AI Support & Instant Answer for Elementor & Gutenberg Key Information: Software Type: Plugin Software Slug: betterdocs Software Status: Active Software Author: wpdevteam Software Downloads: 1,219,559 Active Installs: 30,000 Last Updated: March 26, 2024 Patched Versions: 3.5.0 Affected Versions: <= 3.4.2 Vulnerability Details:…

Read More

Post and Page Builder by BoldGrid Vulnerability – Visual Drag and Drop Editor – Authenticated (Contributor+) Stored Cross-Site Scripting |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Post and Page Builder by BoldGrid Vulnerability – Visual Drag and Drop Editor - Authenticated (Contributor+) Stored Cross-Site Scripting |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Post and Page Builder by BoldGrid – Visual Drag and Drop Editor Key Information: Software Type: Plugin Software Slug: post-and-page-builder Software Status: Active Software Author: BoldGrid Software Downloads: 1,381,114 Active Installs: 80,000 Last Updated: March 25, 2024 Patched Versions: 1.26.3 Affected Versions: <= 1.26.2 Vulnerability Details: Name: Post and Page Builder by BoldGrid…

Read More

Real Media Library: Media Library Folder & File Manager – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-2027 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Real Media Library: Media Library Folder & File Manager - Authenticated (Contributor+) Stored Cross-Site Scripting - CVE-2024-2027 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Real Media Library: Media Library Folder & File Manager Key Information: Software Type: Plugin Software Slug: real-media-library-lite Software Status: Active Software Author: devowl Software Downloads: 2,429,162 Active Installs: 80,000 Last Updated: March 25, 2024 Patched Versions: 4.22.8 Affected Versions: <= 4.22.7 Vulnerability Details: Name: Real Media Library: Media Library Folder & File Manager…

Read More

Affiliate Links, Link Branding, Link Tracking & Marketing Plugin Vulnerability – Cross-Site Request Forgery to Plugin Settings Update – CVE-2024-2326 |WordPress Plugin Vulnerability Report – Pretty Links

WP Plugin Vulnerabilities Image - Affiliate Links, Link Branding, Link Tracking & Marketing Plugin Vulnerability - Cross-Site Request Forgery to Plugin Settings Update - CVE-2024-2326 |WordPress Plugin Vulnerability Report - Pretty Links - Vulnerabilities

Plugin Name: Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin Key Information: Software Type: Plugin Software Slug: pretty-link Software Status: Active Software Author: supercleanse Software Downloads: 7,316,398 Active Installs: 300,000 Last Updated: March 22, 2024 Patched Versions: 3.6.4 Affected Versions: <= 3.6.3 Vulnerability Details: Name: Pretty Links <= 3.6.3 Title: Cross-Site…

Read More