Stored Cross-Site Scripting

GiveWP Vulnerability– Donation Plugin and Fundraising Platform – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1424 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 19, 2024

Plugin Name: GiveWP – Donation Plugin and Fundraising Platform Key Information: Software Type: Plugin Software Slug: give Software Status: Active Software Author: webdevmattcrom Software Downloads: 6,822,276 Active Installs: 100,000 Last Updated: March 19, 2024 Patched Versions: 3.6.0 Affected Versions: <= 3.5.1 Vulnerability Details: Name: GiveWP – Donation Plugin and Fundraising Platform <= 3.5.1 Title: Authenticated…

Elementor Addons by Livemesh Vulnerability – Authenticated Stored Cross-Site Scripting via Posts Multislider Widget – CVE-2024-1466 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Mar 13, 2024

Plugin Name: Elementor Addons by Livemesh Key Information: Software Type: Plugin Software Slug: addons-for-elementor Software Status: Active Software Author: livemesh Software Downloads: 3,775,245 Active Installs: 70,000 Last Updated: March 14, 2024 Patched Versions: 8.3.6 Affected Versions: <= 8.3.4 Vulnerability Details: Name: Elementor Addons by Livemesh <= 8.3.4 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Posts…

 Colibri Page Builder Vulnerability – Missing Authorization – CVE-2024-1870 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Mar 8, 2024

Plugin Name: Colibri Page Builder Key Information: Software Type: Plugin Software Slug: colibri-page-builder Software Status: Active Software Author: extendthemes Software Downloads: 2,440,741 Active Installs: 100,000 Last Updated: March 13, 2024 Patched Versions: 1.0.263 Affected Versions: <= 1.0.260 Vulnerability Details: Name: Colibri Page Builder <= 1.0.260 Title: Missing Authorization Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVE: CVE-2024-1870 CVSS Score: 4.3…

Visual Composer Vulnerability – Authenticated Contributor+ Stored Cross-Site Scripting – CVE-2023-6880 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 29, 2024

Plugin Name: Visual Composer Website Builder, Landing Page Builder, Custom Theme Builder, Maintenance Mode & Coming Soon Pages Key Information: Software Type: Plugin Software Slug: visualcomposer Software Status: Active Software Author: visualcomposer Software Downloads: 2,579,334 Active Installs: 60,000 Last Updated: March 1, 2024 Patched Versions: <= 45.6.0 Affected Versions: 45.7.0 Vulnerability Details: Name: Visual Composer…

Essential Blocks Vulnerability- Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2024-1854 | WordPress Plugin Vulnerability Report

By Your WP Guy / Feb 28, 2024

Plugin Name: Essential Blocks Key Information: Software Type: Plugin Software Slug: essential-blocks Software Status: Active Software Author: wpdevteam Software Downloads: 2,615,695 Active Installs: 100,000 Last Updated: February 28, 2024 Patched Versions: <= 4.5.1 Affected Versions: 4.5.2 Vulnerability Details: Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates <= 4.5.1 Title: Authenticated (Contributor+) Stored…

Starbox Vulnerability– the Author Box for Humans – Authenticated (Subscriber+) Stored Cross-Site Scripting via Job Settings – CVE-2023-6806 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Feb 6, 2024

Plugin Name: Starbox – the Author Box for Humans Key Information: Software Type: Plugin Software Slug: starbox Software Status: Active Software Author: cifi Software Downloads: 449,615 Active Installs: 50,000 Last Updated: February 13, 2024 Patched Versions: 3.5.0 Affected Versions: <= 3.4.8 Vulnerability Details: Name: Starbox <= 3.4.8 Title: Authenticated (Subscriber+) Stored Cross-Site Scripting via Job…

Schema & Structured Data for WP & AMP – Authenticated Stored Cross-Site Scripting – CVE-2024-22146 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 12, 2024

Plugin Name: Schema & Structured Data for WP & AMP Key Information: Software Type: Plugin Software Slug: schema-and-structured-data-for-wp Software Status: Active Software Author: magazine3 Software Downloads: 4,852,104 Active Installs: 100,000 Last Updated: January 12, 2024 Patched Versions: 1.26 Affected Versions: <= 1.25 Vulnerability Details: Name: Schema & Structured Data for WP & AMP <= 1.25…

Email Encoder Vulnerability – Protect Email Addresses and Phone Numbers – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7070 |WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Email Encoder – Protect Email Addresses and Phone Numbers Key Information: Software Type: Plugin Software Slug: email-encoder-bundle Software Status: Active Software Author: ironikus Software Downloads: 996,589 Active Installs: 80,000 Last Updated: January 9, 2024 Patched Versions: 2.1.10 Affected Versions: <= 2.1.9 Vulnerability Details: Name: Email Encoder <= 2.1.9 Title: Authenticated (Contributor+) Stored Cross-Site…

Essential Blocks Vulnerability – Page Builder Gutenberg Blocks, Patterns & Templates – Authenticated (Contributor+) Stored Cross-Site Scripting – CVE-2023-7071 | WordPress Plugin Vulnerability Report

By Your WP Guy / Jan 9, 2024

Plugin Name: Essential Blocks – Page Builder Gutenberg Blocks, Patterns & Templates Key Information: Software Type: Plugin Software Slug: essential-blocks Software Status: Active Software Author: wpdevteam Software Downloads: 2,305,018 Active Installs: 100,000 Last Updated: January 9, 2024 Patched Versions: 4.4.7 Affected Versions: <= 4.4.6 Vulnerability Details: Name: Essential Blocks <= 4.4.6 Title: Authenticated (Contributor+) Stored…

Happy Addons for Elementor – Authenticated (Contributor+) Stored Cross-Site Scripting |WordPress Plugin Vulnerability Report 

By Your WP Guy / Jan 9, 2024

Plugin Name: Happy Addons for Elementor Key Information: Software Type: Plugin Software Slug: happy-elementor-addons Software Status: Active Software Author: thehappymonster Software Downloads: 5,771,889 Active Installs: 400,000 Last Updated: January 9, 2024 Patched Versions: 3.10.1 Affected Versions: <= 3.10.0 Vulnerability Details: Name: Happy Elementor Addons <= 3.10.0 Title: Authenticated (Contributor+) Stored Cross-Site Scripting Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N CVE:…