XSS vulnerability

WP Plugin Vulnerabilities Image - Prime Slider Vulnerability - Authenticated Stored Cross-Site Scripting via Rubix Widget - CVE-2024-1507 | WordPress Plugin Vulnerability Report - XSS vulnerability

Prime Slider Vulnerability – Authenticated Stored Cross-Site Scripting via Rubix Widget – CVE-2024-1507 | WordPress Plugin Vulnerability Report – 

By Your WP Guy / Mar 12, 2024

Plugin Name: Prime Slider – Addons For Elementor Key Information: Software Type: Plugin Software Slug: bdthemes-prime-slider-lite Software Status: Active Software Author: bdthemes Software Downloads: 2,042,074 Active Installs: 100,000 Last Updated: March 13, 2024 Patched Versions: 3.13.3 Affected Versions: <= 3.13.2 Vulnerability Details: Name: Prime Slider – Addons For Elementor <= 3.13.2 Title: Authenticated (Contributor+) Stored…

Read More
WP Plugin Vulnerabilities Image -  Colibri Page Builder Vulnerability - Missing Authorization - CVE-2024-1870 | WordPress Plugin Vulnerability Report  - XSS vulnerability

 Colibri Page Builder Vulnerability – Missing Authorization – CVE-2024-1870 | WordPress Plugin Vulnerability Report 

By Your WP Guy / Mar 8, 2024

Plugin Name: Colibri Page Builder Key Information: Software Type: Plugin Software Slug: colibri-page-builder Software Status: Active Software Author: extendthemes Software Downloads: 2,440,741 Active Installs: 100,000 Last Updated: March 13, 2024 Patched Versions: 1.0.263 Affected Versions: <= 1.0.260 Vulnerability Details: Name: Colibri Page Builder <= 1.0.260 Title: Missing Authorization Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N CVE: CVE-2024-1870 CVSS Score: 4.3…

Read More
WP Plugin Vulnerabilities Image - Ultimate Member Vulnerability - Unauthenticated Stored Cross-Site Scripting - CVE-2024-2123 |WordPress Plugin Vulnerability Report - XSS vulnerability

Ultimate Member Vulnerability – Unauthenticated Stored Cross-Site Scripting – CVE-2024-2123 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 8, 2024

Plugin Name: Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin Key Information: Software Type: Plugin Software Slug: ultimate-member Software Status: Active Software Author: ultimatemember Software Downloads: 9,871,019 Active Installs: 200,000 Last Updated: March 12, 2024 Patched Versions: 2.8.4 Affected Versions: <= 2.8.3 Vulnerability Details: Name: Ultimate Member <= 2.8.3…

Read More
WP Plugin Vulnerabilities Image - Metform Elementor Contact Form Builder Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode - CVE-2024-1585 |WordPress Plugin Vulnerability Report - XSS vulnerability

Metform Elementor Contact Form Builder Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode – CVE-2024-1585 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 7, 2024

Plugin Name: Metform Elementor Contact Form Builder Key Information: Software Type: Plugin Software Slug: metform Software Status: Active Software Author: xpeedstudio Software Downloads: 3,185,155 Active Installs: 300,000 Last Updated: March 12, 2024 Patched Versions: 3.8.4 Affected Versions: <= 3.8.3 Vulnerability Details: Name: Metform Elementor Contact Form Builder <= 3.8.3 Title: Authenticated (Contributor+) Stored Cross-Site Scripting…

Read More
WP Plugin Vulnerabilities Image - Orbit Fox by ThemeIsle Vulnerability - Authenticated (Contributor+) Stored Cross-Site Scripting via Registration Form Widget - CVE-2024-2126 |WordPress Plugin Vulnerability Report  - XSS vulnerability

Orbit Fox by ThemeIsle Vulnerability – Authenticated (Contributor+) Stored Cross-Site Scripting via Registration Form Widget – CVE-2024-2126 |WordPress Plugin Vulnerability Report 

By Your WP Guy / Mar 7, 2024

Plugin Name: Orbit Fox by ThemeIsle Key Information: Software Type: Plugin Software Slug: themeisle-companion Software Status: Active Software Author: ThemeIsle Software Downloads: 11,445,655 Active Installs: 200,000 Last Updated: March 12, 2024 Patched Versions: 2.10.33 Affected Versions: <= 2.10.32 Vulnerability Details: Name: Orbit Fox by ThemeIsle <= 2.10.32 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Registration…

Read More
WP Plugin Vulnerabilities Image - Page Builder: Pagelayer Vulnerability– Drag and Drop website builder - Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes - CVE-2024-2127 |WordPress Plugin Vulnerability Report - XSS vulnerability

Page Builder: Pagelayer Vulnerability– Drag and Drop website builder – Authenticated (Contributor+) Stored Cross-Site Scripting via Custom Attributes – CVE-2024-2127 |WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 7, 2024

Plugin Name: Page Builder: Pagelayer – Drag and Drop website builder Key Information: Software Type: Plugin Software Slug: pagelayer Software Status: Active Software Author: softaculous Software Downloads: 5,791,472 Active Installs: 200,000 Last Updated: March 12, 2024 Patched Versions: 1.8.4 Affected Versions: <= 1.8.3 Vulnerability Details: Name: Page Builder: Pagelayer – Drag and Drop website builder…

Read More
WP Plugin Vulnerabilities Image - WP-Members Membership Plugin - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode - CVE-2024-1987 | WordPress Plugin Vulnerability Report - XSS vulnerability

WP-Members Membership Plugin – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode – CVE-2024-1987 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 7, 2024

Plugin Name: WP-Members Membership Plugin Key Information: Software Type: Plugin Software Slug: wp-members Software Status: Active Software Author: cbutlerjr Software Downloads: 3,443,217 Active Installs: 60,000 Last Updated: March 12, 2024 Patched Versions: 3.4.9.2 Affected Versions: <= 3.4.9.1 Vulnerability Details: Name: WP-Members Membership Plugin <= 3.4.9.1 Title: Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Type: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N…

Read More
WP Plugin Vulnerabilities Image - EmbedPress – Embed Various Content Types - Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget - CVE-2024-2128 | WordPress Plugin Vulnerability Report - XSS vulnerability

EmbedPress – Embed Various Content Types – Authenticated (Contributor+) Stored Cross-Site Scripting via EmbedPress PDF Widget – CVE-2024-2128 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 7, 2024

Plugin Name: EmbedPress – Embed PDF, Google Docs, Vimeo, Wistia, Embed YouTube Videos, Audios, Maps & Embed Any Documents in Gutenberg & Elementor Key Information: Software Type: Plugin Software Slug: embedpress Software Status: Active Software Author: wpdevteam Software Downloads: 2,279,058 Active Installs: 90,000 Last Updated: March 12, 2024 Patched Versions: 3.9.11 Affected Versions: <= 3.9.10…

Read More
WP Plugin Vulnerabilities Image - User Registration Vulnerability– Custom Registration Form, Login Form, and User Profile WordPress Plugin - Unauthenticated Stored Self-Based Cross-Site Scripting - CVE-2024-1720 | WordPress Plugin Vulnerability Report - XSS vulnerability

User Registration Vulnerability– Custom Registration Form, Login Form, and User Profile WordPress Plugin – Unauthenticated Stored Self-Based Cross-Site Scripting – CVE-2024-1720 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 6, 2024

Plugin Name: User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin Key Information: Software Type: Plugin Software Slug: user-registration Software Status: Active Software Author: wpeverest Software Downloads: 2,562,763 Active Installs: 60,000 Last Updated: March 8, 2024 Patched Versions: 3.1.5 Affected Versions: <= 3.1.4 Vulnerability Details: Name: User Registration – Custom Registration…

Read More
WP Plugin Vulnerabilities Image - Royal Elementor Addons and Templates - Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget - CVE-2024-1500 | WordPress Plugin Vulnerability Report - XSS vulnerability

Royal Elementor Addons and Templates – Authenticated (Contributor+) Stored Cross-Site Scripting via Logo Widget – CVE-2024-1500 | WordPress Plugin Vulnerability Report

By Your WP Guy / Mar 6, 2024

Plugin Name: Royal Elementor Addons and Templates Key Information: Software Type: Plugin Software Slug: royal-elementor-addons Software Status: Active Software Author: wproyal Software Downloads: 4,248,687 Active Installs: 300,000 Last Updated: March 8, 2024 Patched Versions: Information not provided Affected Versions: <= 1.3.91 Vulnerability Details: Name: Royal Elementor Addons and Templates <= 1.3.91 Title: Authenticated (Contributor+) Stored…

Read More