A vulnerability was found in 10Web Form Maker Plugin up to 1.15.30 on WordPress. It has been classified as problematic. Affected is an unknown function of the component Setting Handler. The manipulation leads to cross site scripting.
This vulnerability is traded as CVE-2024-10562. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Rbs Image Gallery Plugin up to 3.2.21 on WordPress and classified as problematic. This issue affects some unknown processing of the component Photo Gallery/Images/Slider. The manipulation leads to cross site scripting.
The identification of this vulnerability is CVE-2024-10102. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in a3rev Compare Products for WooCommerce Plugin up to 3.2.1 on WordPress. Affected by this issue is some unknown functionality. The manipulation of the argument s_feature leads to cross site scripting.
This vulnerability is handled as CVE-2024-12435. The attack may be launched remotely. There is no exploit available.
A vulnerability classified as problematic has been found in 1clickdesigns ClickDesigns Plugin up to 1.8.0 on WordPress. Affected is the function clickdesigns_add_api/clickdesigns_remove_api. The manipulation leads to missing authorization.
This vulnerability is traded as CVE-2024-12559. It is possible to launch the attack remotely. There is no exploit available.
Experts spotted new variants of the Eagerbee backdoor being used in attacks on government organizations and ISPs in the Middle East. Kaspersky researchers reported that new variants of the Eagerbee backdoor being used in attacks against Internet Service Providers (ISPs) and government entities in the Middle East. The Kaspersky’s analysis revealed new attack components, including […]
A vulnerability was found in binsaifullah Duplicate Post, Page and Any Custom Post plugin up to 3.5.3 on WordPress. It has been rated as problematic. This issue affects the function dpp_duplicate_as_draft of the component Password Protected Post Handler. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-12538. The attack may be initiated remotely. There is no exploit available.
A vulnerability was found in jdsofttech School Management System Plugin up to 2.2.14 on WordPress. It has been declared as critical. This vulnerability affects unknown code. The manipulation of the argument cid leads to sql injection.
This vulnerability was named CVE-2024-12332. The attack can be initiated remotely. There is no exploit available.
A vulnerability was found in proloybhaduri LazyLoad Background Images Plugin up to 1.0.7 on WordPress. It has been classified as problematic. This affects the function pblzbg_save_settings of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is uniquely identified as CVE-2024-12327. It is possible to initiate the attack remotely. There is no exploit available.
A vulnerability was found in WordLift Plugin up to 3.54.0 on WordPress and classified as problematic. Affected by this issue is the function wl_config_plugin of the component Setting Handler. The manipulation leads to missing authorization.
This vulnerability is handled as CVE-2024-12176. The attack may be launched remotely. There is no exploit available.
A vulnerability has been found in arrowplugins Popup Plugin up to 3.2.6 on WordPress and classified as problematic. Affected by this vulnerability is the function upc_delete_db_data. The manipulation leads to missing authorization.
This vulnerability is known as CVE-2024-12158. The attack can be launched remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in arrowplugins Popup Plugin up to 3.2.6 on WordPress. Affected is the function upc_delete_db_record. The manipulation of the argument id leads to sql injection.
This vulnerability is traded as CVE-2024-12157. It is possible to launch the attack remotely. There is no exploit available.
A vulnerability, which was classified as problematic, has been found in aiwp Elementor Addons AI Addons Plugin up to 2.2.1 on WordPress. This issue affects the function render. The manipulation leads to information disclosure.
The identification of this vulnerability is CVE-2024-12140. The attack may be initiated remotely. There is no exploit available.