Plugin Updates
LearnPress Vulnerability – WordPress LMS Plugin – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-3560 | WordPress Plugin Vulnerability Report
Plugin Name: LearnPress – WordPress LMS Plugin Key Information: Software Type: Plugin Software Slug: learnpress Software Status: Active Software Author: thimpress Software Downloads: 4,188,254 Active Installs: 90,000 Last Updated: May 2, 2024 Patched Versions: 4.2.6.5 Affected Versions: <= 4.2.6.4 Vulnerability Details: Name: LearnPress – WordPress LMS Plugin <= 4.2.6.4 Title: Authenticated (Contributor+) Stored Cross-Site Scripting…
Backup Migration Vulnerability – Information Exposure via Log Files – CVE-2024-32686 | WordPress Plugin Vulnerability Report
Plugin Name: Backup Migration Key Information: Software Type: Plugin Software Slug: backup-backup Software Status: Active Software Author: inisev Software Downloads: 1,449,047 Active Installs: 80,000 Last Updated: May 2, 2024 Patched Versions: 1.4.4 Affected Versions: <= 1.4.3 Vulnerability Details: Name: Backup Migration <= 1.4.3 Title: Information Exposure via Log Files Type: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVE: CVE-2024-32686 CVSS Score:…
Click to Chat Vulnerability – HoliThemes – Authenticated (Contributor+) Local File Inclusion – CVE-2024-3849 |WordPress Plugin Vulnerability Report
Plugin Name: Click to Chat – HoliThemes Key Information: Software Type: Plugin Software Slug: click-to-chat-for-whatsapp Software Status: Active Software Author: holithemes Software Downloads: 11,311,845 Active Installs: 500,000 Last Updated: May 2, 2024 Patched Versions: 4.0 Affected Versions: <= 3.35 Vulnerability Details: Name: Click to Chat – HoliThemes <= 3.35 Title: Authenticated (Contributor+) Local File Inclusion…
HT Mega Vulnerability – Absolute Addons For Elementor – Multiple Vulnerabilities – Various CVEs |WordPress Plugin Vulnerability Report
Plugin Name: HT Mega – Absolute Addons For Elementor Key Information: Software Type: Plugin Software Slug: ht-mega-for-elementor Software Status: Active Software Author: devitemsllc Software Downloads: 3,754,207 Active Installs: 100,000 Last Updated: April 26, 2024 Patched Versions: 2.4.7, 2.4.9 Affected Versions: <= 2.4.6, <= 2.4.8 Vulnerability Details: Name: HT Mega – Absolute Addons For Elementor <=…
Otter Blocks Vulnerability – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE – Authenticated Stored Cross-Site Scripting via ‘titleTag’ – CVE-2024-3725 | WordPress Plugin Vulnerability Report
Plugin Name: Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE Key Information: Software Type: Plugin Software Slug: otter-blocks Software Status: Active Software Author: themeisle Software Downloads: 7,631,372 Active Installs: 300,000 Last Updated: April 25, 2024 Patched Versions: 2.6.10 Affected Versions: <= 2.6.9 Vulnerability Details: Name: Otter Blocks <= 2.6.9 Title: Authenticated…
Enhanced Media Library Vulnerability – Authenticated (Author+) Stored Cross-Site Scripting – CVE-2024-2840 | WordPress Plugin Vulnerability Report
Plugin Name: Enhanced Media Library Key Information: Software Type: Plugin Software Slug: enhanced-media-library Software Status: Active Software Author: webbistro Software Downloads: 2,252,374 Active Installs: 90,000 Last Updated: April 25, 2024 Patched Versions: 2.8.10 Affected Versions: <= 2.8.9 Vulnerability Details: Name: Enhanced Media Library <= 2.8.9 Title: Authenticated (Author+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVE: CVE-2024-2840…
Customer Reviews for WooCommerce Vulnerability – Multiple Vulnerabilities – CVE-2024-3869 & CVE-2024-3243 | WordPress Plugin Vulnerability Report
Plugin Name: Customer Reviews for WooCommerce Key Information: Software Type: Plugin Software Slug: customer-reviews-woocommerce Software Status: Active Software Author: ivole Software Downloads: 4,223,317 Active Installs: 60,000 Last Updated: April 25, 2024 Patched Versions: 5.47.0 Affected Versions: <= 5.46.0 Vulnerability Details: Vulnerability 1: Name: Customer Reviews for WooCommerce <= 5.46.0 Title: Missing Authorization to Authenticated (Subscriber+)…
Exclusive Addons for Elementor Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via InfoBox – CVE-2024-2751 | WordPress Plugin Vulnerability Report
Plugin Name: Exclusive Addons for Elementor Key Information: Software Type: Plugin Software Slug: exclusive-addons-for-elementor Software Status: Active Software Author: timstrifler Software Downloads: 814,796 Active Installs: 60,000 Last Updated: April 25, 2024 Patched Versions: 2.6.9.3 Affected Versions: <= 2.6.9.2 Vulnerability Details: Name: Exclusive Addons for Elementor <= 2.6.9.2 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via InfoBox…
Paid Memberships Pro Vulnerability – Content Restriction, User Registration, & Paid Subscriptions – Cross-Site Request Forgery – CVE-2024-3215 | WordPress Plugin Vulnerability Report
Plugin Name: Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions Key Information: Software Type: Plugin Software Slug: paid-memberships-pro Software Status: Active Software Author: strangerstudios Software Downloads: 5,775,005 Active Installs: 90,000 Last Updated: April 25, 2024 Patched Versions: 3.0.2 Affected Versions: <= 3.0.1 Vulnerability Details: Name: Paid Memberships Pro <= 3.0.1 Title: Cross-Site…