A vulnerability described as problematic has been identified in Exclusive Addons for Elementor Plugin up to 2.6.8 on WordPress. Affected by this vulnerability is an unknown functionality. Executing a manipulation can lead to cross site scripting.
This vulnerability appears as CVE-2024-0823. The attack may be performed from remote. There is no available exploit.
A vulnerability, which was classified as critical, was found in Instant Images Plugin up to 6.1.0 on WordPress. Affected by this issue is some unknown functionality of the component Options Update Handler. Executing a manipulation can lead to improper authentication.
This vulnerability is tracked as CVE-2024-0869. The attack can be launched remotely. No exploit exists.
A vulnerability has been found in SiteOrigin Widgets Bundle Plugin up to 1.58.1 on WordPress and classified as problematic. This affects an unknown part. The manipulation leads to cross site scripting.
This vulnerability is listed as CVE-2024-0961. The attack may be initiated remotely. There is no available exploit.
A vulnerability was found in Affiliates Manager Plugin up to 2.9.34 on WordPress and classified as problematic. Affected is an unknown function. The manipulation results in cross-site request forgery.
This vulnerability was named CVE-2024-0859. The attack may be performed from remote. There is no available exploit.
A vulnerability described as critical has been identified in SeedProd Website Builder Plugin up to 6.15.21 on WordPress. Affected by this vulnerability is the function seedprod_lite_new_lpage. The manipulation results in missing authorization.
This vulnerability is identified as CVE-2024-1072. The attack can be executed remotely. There is not any exploit available.
A vulnerability, which was classified as problematic, was found in Active Products Tables for WooCommerce Plugin up to 1.0.6.1 on WordPress. This issue affects some unknown processing. Executing a manipulation can lead to missing authorization.
This vulnerability is registered as CVE-2024-0797. It is possible to launch the attack remotely. No exploit is available.
A vulnerability marked as critical has been reported in ARMember Plugin up to 4.0.24 on WordPress. Affected is an unknown function of the component REST API. Performing a manipulation results in improper access controls.
This vulnerability is cataloged as CVE-2024-0969. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability categorized as critical has been discovered in Feedzy RSS Aggregator Plugin up to 4.4.1 on WordPress. This impacts an unknown function. Executing a manipulation can lead to missing authorization.
This vulnerability appears as CVE-2024-1092. The attack may be performed from remote. There is no available exploit.
A vulnerability identified as critical has been detected in WP Club Manager Plugin up to 2.2.10 on WordPress. The affected element is an unknown function of the component Event Permalink Update Handler. The manipulation leads to missing authorization.
This vulnerability is listed as CVE-2024-1177. The attack must be carried out from within the local network. There is no available exploit.
A vulnerability marked as critical has been reported in Advanced Forms for ACF Plugin up to 1.9.3.2 on WordPress. This affects an unknown function of the component Form Setting Export. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2024-1121. The attack requires access to the local network. No exploit is available.
A vulnerability classified as problematic has been found in wproyal Royal Elementor Kit Plugin up to 1.0.116 on WordPress. Impacted is an unknown function of the component Transient Update Handler. This manipulation causes missing authorization.
This vulnerability is registered as CVE-2024-0835. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability marked as problematic has been reported in webfactory Minimal Coming Soon Plugin up to 2.37 on WordPress. This issue affects some unknown processing of the component Maintenance Mode. This manipulation causes authorization bypass.
The identification of this vulnerability is CVE-2024-1075. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability classified as problematic has been found in wpdevteam Essential Addons for Elementor Plugin up to 5.9.7 on WordPress. The affected element is an unknown function of the component data-eael-wrapper-link Wrapper. Performing a manipulation results in cross site scripting.
This vulnerability is identified as CVE-2024-0954. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability categorized as critical has been discovered in Cockpit. Affected is an unknown function of the component Remote Login. The manipulation results in os command injection.
This vulnerability is known as CVE-2026-4631. It is possible to launch the attack remotely. No exploit is available.
A vulnerability described as problematic has been identified in Rack up to 2.2.22/3.1.20/3.2.5. This vulnerability affects the function Rack::Static of the file /css of the component Request Path Handler. Executing a manipulation can lead to partial string comparison.
This vulnerability is registered as CVE-2026-34785. It is possible to launch the attack remotely. No exploit is available.
Upgrading the affected component is recommended.