Beaver Builder Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-0897 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Beaver Builder Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting - CVE-2024-0897 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Beaver Builder Key Information: Software Type: Plugin Software Slug: beaver-builder-lite-version Software Status: Active Software Author: justinbusa Software Downloads: 9,597,835 Active Installs: 100,000 Last Updated: February 20, 2024 Patched Versions: 2.7.4.3 Affected Versions: <= 2.7.4.2 Vulnerability Details: Name: Beaver Builder – WordPress Page Builder <= 2.7.4.2 – Authenticated (Contributor+) Stored Cross-Site Scripting Type: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)…

Read More

3D FlipBook Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks – CVE-2024-1081 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - 3D FlipBook Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks - CVE-2024-1081 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: 3D FlipBook Key Information: Software Type: Plugin Software Slug: interactive-3d-flipbook-powered-physics-engine Software Status: Active Software Author: iberezansky Software Downloads: 1,524,371 Active Installs: 70,000 Last Updated: February 20, 2024 Patched Versions: 1.15.4 Affected Versions: <= 1.15.3 Vulnerability Details: Name: 3D FlipBook – PDF Flipbook WordPress <= 1.15.3 – Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Bookmarks Type: Improper Neutralization of…

Read More

Schema & Structured Data for WP & AMP Vulnerability – Missing Authorization to reCaptcha Key Modification & Authenticated (Custom) Stored Cross-Site Scripting – CVE-2024-1288 & CVE-2024-1586 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Schema & Structured Data for WP & AMP Vulnerability - Missing Authorization to reCaptcha Key Modification & Authenticated (Custom) Stored Cross-Site Scripting - CVE-2024-1288 & CVE-2024-1586 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Schema & Structured Data for WP & AMP Key Information: Software Type: Plugin Software Slug: schema-and-structured-data-for-wp Software Status: Active Software Author: magazine3 Software Downloads: 4,923,980 Active Installs: 100,000 Last Updated: February 19, 2024 Patched Versions: 1.27 Affected Versions: <= 1.26 Vulnerability 1 Details: Name: Schema & Structured Data for WP & AMP <=…

Read More

Featured Image from URL Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via fifu_input_url – CVE-2024-1496 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Featured Image from URL Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via fifu_input_url - CVE-2024-1496 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Featured Image from URL Key Information: Software Type: Plugin Software Slug: featured-image-from-url Software Status: Active Software Author: marceljm Software Downloads: 4,896,915 Active Installs: 100,000 Last Updated: February 19, 2024 Patched Versions: 4.6.3 Affected Versions: <= 4.6.2 Vulnerability Details: Name: Featured Image from URL (FIFU) <= 4.6.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via…

Read More

Password Protected Vulnerability – Authenticated (Admin+) Stored Cross-Site Scripting – CVE-2024-0656 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Password Protected Vulnerability - Authenticated (Admin+) Stored Cross-Site Scripting - CVE-2024-0656 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Password Protected Key Information: Software Type: Plugin Software Slug: password-protected Software Status: Active Software Author: wpexpertsio Software Downloads: 4,493,510 Active Installs: 400,000 Last Updated: February 19, 2024 Patched Versions: 2.6.7 Affected Versions: <= 2.6.6 Vulnerability Details: Name: Password Protected <= 2.6.6 – Authenticated (Admin+) Stored Cross-Site Scripting Title: Authenticated (Admin+) Stored Cross-Site Scripting Type: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic…

Read More

Shortcodes Ultimate Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via su_tooltip Shortcode – CVE-2024-1510 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Shortcodes Ultimate Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via su_tooltip Shortcode - CVE-2024-1510 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Shortcodes Ultimate Key Information ormation: Software Type: Plugin Software Slug: shortcodes-ultimate Software Status: Active Software Author: gn_themes Software Downloads: 18,644,577 Active Installs: 600,000 Last Updated: February 19, 2024 Patched Versions: 7.0.3 Affected Versions: <= 7.0.2 Vulnerability Details: Name: WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.2 – Authenticated (Contributor+) Stored Cross-Site Scripting via su_tooltip Shortcode Type: Improper Neutralization of Input During Web Page Generation…

Read More

Ocean Extra Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1277 | WordPress Plugin Vulnerability Report 

WP Plugin Vulnerabilities Image - Ocean Extra Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting - CVE-2024-1277 | WordPress Plugin Vulnerability Report  - Vulnerabilities

Plugin Name: Ocean Extra Key Information: Software Type: Plugin Software Slug: ocean-extra Software Status: Active Software Author: oceanwp Software Downloads: 20,016,876 Active Installs: 700,000 Last Updated: February 27, 2024 Patched Versions: 2.2.5 Affected Versions: <= 2.2.4 Vulnerability Details: Name: Ocean Extra <= 2.2.4 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-1277 CVSS Score:…

Read More

Page scroll to id – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode – CVE-2024-1445 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Page scroll to id - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode - CVE-2024-1445 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Page scroll to id Key Information: Software Type: Plugin Software Slug: page-scroll-to-id Software Status: Active Software Author: malihu Software Downloads: 1,684,219 Active Installs: 100,000 Last Updated: February 27, 2024 Patched Versions: 1.7.9 Affected Versions: <= 1.7.8 Vulnerability Details: Name: Page scroll to id <= 1.7.8 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode…

Read More

WP Maintenance Vulnerability – Information Exposure – CVE-2024-1472 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - WP Maintenance Vulnerability - Information Exposure - CVE-2024-1472 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: WP Maintenance Key Information: Software Type: Plugin Software Slug: wp-maintenance Software Status: Active Software Author: florent73 Software Downloads: 903,892 Active Installs: 50,000 Last Updated: February 27, 2024 Patched Versions: 6.1.7 Affected Versions: <= 6.1.6 Vulnerability Details: Name: WP Maintenance <= 6.1.6 Title: Information Exposure Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2024-1472 CVSS Score: 5.3 Publicly Published:…

Read More