Booster for WooCommerce Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1054 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Booster for WooCommerce Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting - CVE-2024-1054 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Booster for WooCommerce Key Information: Software Type: Plugin Software Slug: woocommerce-jetpack Software Status: Active Software Author: pluggabl Software Downloads: 3,564,084 Active Installs: 50,000 Last Updated: February 27, 2024 Patched Versions: 7.1.7 Affected Versions: <= 7.1.6 Vulnerability Details: Name: Booster for WooCommerce <= 7.1.6 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE: CVE-2024-1054…

Read More

Essential Addons for Elementor Vulnerability– Best Elementor Templates, Widgets, Kits & WooCommerce Builders – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1236 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - Essential Addons for Elementor Vulnerability– Best Elementor Templates, Widgets, Kits & WooCommerce Builders - Authenticated (Contributor+) Stored Cross-Site Scripting - CVE-2024-1236 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: Essential Addons for Elementor – Best Elementor Templates, Widgets, Kits & WooCommerce Builders Key Information: Software Type: Plugin Software Slug: essential-addons-for-elementor-lite Software Status: Active Software Author: wpdevteam Software Downloads: 66,915,084 Active Installs: 2,000,000 Last Updated: February 27, 2024 Patched Versions: 5.9.9 Affected Versions: <= 5.9.8 Vulnerability Details: Name: Essential Addons for Elementor <=…

Read More

RSS Aggregator by Feedzy Vulnerability– Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator – Missing Authorization to Arbitrary Page Creation and Publication – CVE-2024-1318 | WordPress Plugin Vulnerability Report

Plugin Name: RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator Key Information: Software Type: Plugin Software Slug: feedzy-rss-feeds Software Status: Active Software Author: themeisle Software Downloads: 2,093,546 Active Installs: 50,000 Last Updated: February 13, 2024 Patched Versions: 4.4.3 Affected Versions: <= 4.4.2 Vulnerability Details: Name: RSS Aggregator by…

Read More

Insert PHP Code Snippet Vulnerability – Authenticated (Admin+) Stored Cross-Site Scripting – CVE-2024-0658 |WordPress Plugin Vulnerability Report 

WP Plugin Vulnerabilities Image - Insert PHP Code Snippet Vulnerability - Authenticated (Admin+) Stored Cross-Site Scripting - CVE-2024-0658 |WordPress Plugin Vulnerability Report  - Vulnerabilities

Plugin Name: Insert PHP Code Snippet Key Information: Software Type: Plugin Software Slug: insert-php-code-snippet Software Status: Active Software Author: f1logic Software Downloads: 890,439 Active Installs: 100,000 Last Updated: February 16, 2024 Patched Versions: 1.3.5 Affected Versions: <= 1.3.4 Vulnerability Details: Name: Insert PHP Code Snippet <= 1.3.4 Title: Authenticated (Admin+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N…

Read More

WP Booking Calendar Vulnerability- Unauthenticated SQL Injection – CVE-2024-1207 | WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - WP Booking Calendar Vulnerability- Unauthenticated SQL Injection - CVE-2024-1207 | WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: WP Booking Calendar Key Information: Software Type: Plugin Software Slug: booking Software Status: Active Software Author: wpdevelop Software Downloads: 3,262,200 Active Installs: 60,000 Last Updated: February 12, 2024 Patched Versions: 9.9.1 Affected Versions: <= 9.9 Vulnerability Details: Name: Booking Calendar <= 9.9 Title: Unauthenticated SQL Injection Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVE: CVE-2024-1207 CVSS Score: 9.8…

Read More

WP Recipe Maker Vulnerability- Missing Authorization to Authenticated SQL Injection – CVE-2024-1206 |WordPress Plugin Vulnerability Report

WP Plugin Vulnerabilities Image - WP Recipe Maker Vulnerability- Missing Authorization to Authenticated SQL Injection - CVE-2024-1206 |WordPress Plugin Vulnerability Report - Vulnerabilities

Plugin Name: WP Recipe Maker Key Information: Software Type: Plugin Software Slug: wp-recipe-maker Software Status: Active Software Author: brechtvds Software Downloads: 2,598,010 Active Installs: 50,000 Last Updated: February 13, 2024 Patched Versions: 9.2.0 Affected Versions: <= 9.1.2 Vulnerability Details: Name: WP Recipe Maker <= 9.1.2 Title: Missing Authorization to Authenticated (Subscriber+) SQL Injection Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H…

Read More

WP Shortcodes Plugin Vulnerability— Shortcodes Ultimate – Authenticated Stored Cross-Site Scripting via shortcode – CVE-2024-0792 |WordPress Plugin Vulnerability Report 

WP Plugin Vulnerabilities Image - WP Shortcodes Plugin Vulnerability— Shortcodes Ultimate - Authenticated Stored Cross-Site Scripting via shortcode - CVE-2024-0792 |WordPress Plugin Vulnerability Report  - Vulnerabilities

Plugin Name: WP Shortcodes Plugin — Shortcodes Ultimate Key Information: Software Type: Plugin Software Slug: shortcodes-ultimate Software Status: Active Software Author: gn_themes Software Downloads: 18,460,707 Active Installs: 600,000 Last Updated: February 12, 2024 Patched Versions: 7.0.2 Affected Versions: <= 7.0.1 Vulnerability Details: Name: WP Shortcodes Plugin — Shortcodes Ultimate <= 7.0.1 Title: Authenticated(Contributor+) Stored Cross-Site…

Read More

RSS Aggregator Vulnerability– RSS Import, News Feeds, Feed to Post, and Autoblogging – Authenticated (Admin+) Server-Side Request Forgery via RSS Feed Source – CVE-2024-0628 | WordPress Plugin Vulnerability Report 

WP Plugin Vulnerabilities Image - RSS Aggregator Vulnerability– RSS Import, News Feeds, Feed to Post, and Autoblogging - Authenticated (Admin+) Server-Side Request Forgery via RSS Feed Source - CVE-2024-0628 | WordPress Plugin Vulnerability Report  - Vulnerabilities

Plugin Name: RSS Aggregator – RSS Import, News Feeds, Feed to Post, and Autoblogging Key Information: Software Type: Plugin Software Slug: wp-rss-aggregator Software Status: Active Software Author: jeangalea Software Downloads: 2,636,080 Active Installs: 60,000 Last Updated: February 13, 2024 Patched Versions: 4.23.6 Affected Versions: 4.23.5 – 4.23.5 Vulnerability Details: Name: WP RSS Aggregator <= 4.23.5…

Read More

Starbox Vulnerability– the Author Box for Humans – Authenticated (Subscriber+) Stored Cross-Site Scripting via Job Settings – CVE-2023-6806 | WordPress Plugin Vulnerability Report 

WP Plugin Vulnerabilities Image - Starbox Vulnerability– the Author Box for Humans - Authenticated (Subscriber+) Stored Cross-Site Scripting via Job Settings - CVE-2023-6806 | WordPress Plugin Vulnerability Report  - Vulnerabilities

Plugin Name: Starbox – the Author Box for Humans Key Information: Software Type: Plugin Software Slug: starbox Software Status: Active Software Author: cifi Software Downloads: 449,615 Active Installs: 50,000 Last Updated: February 13, 2024 Patched Versions: 3.5.0 Affected Versions: <= 3.4.8 Vulnerability Details: Name: Starbox <= 3.4.8 Title: Authenticated (Subscriber+) Stored Cross-Site Scripting via Job…

Read More