Plugin Vulnerability
Forminator Vulnerability – Unauthenticated Stored Cross-Site Scripting via File Upload – CVE-2024-1794 | WordPress Plugin Vulnerability Report
Plugin Name: Forminator Key Information: Software Type: Plugin Software Slug: forminator Software Status: Active Software Author: wpmudev Software Downloads: 6,543,744 Active Installs: 500,000 Last Updated: March 29, 2024 Patched Versions: 1.29.1 Affected Versions: <= 1.29.0 Vulnerability Details: Name: Forminator <= 1.29.0 – Unauthenticated Stored Cross-Site Scripting via File Upload Type: Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) CVE: CVE-2024-1794 CVSS Score: 7.2 (High) Publicly Published: March…
WordPress Infinite Scroll Vulnerability – Ajax Load More – Authenticated (Administrator+) Stored Cross-Site Scripting | WordPress Plugin Vulnerability Report
Plugin Name: WordPress Infinite Scroll – Ajax Load More Key Information: Software Type: Plugin Software Slug: ajax-load-more Software Status: Active Software Author: connekthq Software Downloads: 1,881,197 Active Installs: 50,000 Last Updated: April 1, 2024 Patched Versions: 7.0.2 Affected Versions: <= 7.0.1 Vulnerability Details: Name: Ajax Load More <= 7.0.1 Title: Authenticated (Administrator+) Stored Cross-Site Scripting…
VK All in One Expansion Unit – Authenticated (Contributor+) Stored Cross-Site Scripting via className – CVE-2024-2170 |WordPress Plugin Vulnerability Report
Plugin Name: VK All in One Expansion Unit Key Information: Software Type: Plugin Software Slug: vk-all-in-one-expansion-unit Software Status: Active Software Author: kurudrive Software Downloads: 5,085,263 Active Installs: 100,000 Last Updated: March 25, 2024 Patched Versions: 9.97.0.0 Affected Versions: <= 9.96.0.1 Vulnerability Details: Name: VK All in One Expansion Unit <= 9.96.0.1 Title: Authenticated (Contributor+) Stored…
Affiliate Links, Link Branding, Link Tracking & Marketing Plugin Vulnerability – Cross-Site Request Forgery to Plugin Settings Update – CVE-2024-2326 |WordPress Plugin Vulnerability Report – Pretty Links
Plugin Name: Pretty Links – Affiliate Links, Link Branding, Link Tracking & Marketing Plugin Key Information: Software Type: Plugin Software Slug: pretty-link Software Status: Active Software Author: supercleanse Software Downloads: 7,316,398 Active Installs: 300,000 Last Updated: March 22, 2024 Patched Versions: 3.6.4 Affected Versions: <= 3.6.3 Vulnerability Details: Name: Pretty Links <= 3.6.3 Title: Cross-Site…
Advanced Access Manager Vulnerability– Restricted Content, Users & Roles, Enhanced Security and More – Reflected Cross-Site Scripting – CVE-2024-29127 | WordPress Plugin Vulnerability Report
Plugin Name: Advanced Access Manager – Restricted Content, Users & Roles, Enhanced Security and More Key Information: Software Type: Plugin Software Slug: advanced-access-manager Software Status: Active Software Author: vasyltech Software Downloads: 5,341,354 Active Installs: 100,000 Last Updated: March 20, 2024 Patched Versions: 6.9.21 Affected Versions: <= 6.9.20 Vulnerability Details: Name: Advanced Access Manager <= 6.9.20…
Appointment Booking Calendar Vulnerability— Simply Schedule Appointments Booking Plugin – Authenticated (Subscriber+) SQL Injection – CVE-2024-2341 |WordPress Plugin Vulnerability Report
Plugin Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin Key Information: Software Type: Plugin Software Slug: simply-schedule-appointments Software Status: Active Software Author: croixhaug Software Downloads: 963,505 Active Installs: 30,000 Last Updated: March 20, 2024 Patched Versions: 1.6.7.9 Affected Versions: <= 1.6.7.7 Vulnerability Details: Name: Appointment Booking Calendar – Simply Schedule Appointments Booking Plugin…
Smart Custom Fields Vulnerability – Missing Authorization to Authenticated (Subscriber+) Post Content Disclosure – CVE-2024-1995 | WordPress Plugin Vulnerability Report
Plugin Name: Smart Custom Fields Key Information: Software Type: Plugin Software Slug: smart-custom-fields Software Status: Active Software Author: inc2734 Software Downloads: 224,550 Active Installs: 50,000 Last Updated: March 19, 2024 Patched Versions: 5.0.0 Affected Versions: <= 4.2.2 Vulnerability Details: Name: Smart Custom Fields <= 4.2.2 Title: Missing Authorization to Authenticated (Subscriber+) Post Content Disclosure Type:…
Permalink Manager Pro Vulnerability – Missing Authorization to Authenticated (Author+) Arbitrary Post Slug Modification – CVE-2024-2538 | WordPress Plugin Vulnerability Report
Plugin Name: Permalink Manager Pro Key Information: Software Type: Plugin Software Slug: permalink-manager Software Status: Active Software Author: mbis Software Downloads: 1,661,826 Active Installs: 80,000 Last Updated: March 19, 2024 Patched Versions: 2.4.3.2 Affected Versions: <= 2.4.3.1 Vulnerability Details: Name: Permalink Manager <= 2.4.3.1 Title: Missing Authorization to Authenticated (Author+) Arbitrary Post Slug Modification Type:…