Show filters
2,336 Total Results
Displaying 81-90 of 2,336
Sort by:
Attacker Value
Unknown
CVE-2024-12697
Disclosure Date: December 21, 2024 (last updated December 21, 2024)
The real.Kit plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 5.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
0
Attacker Value
Unknown
CVE-2024-54280
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Iqonic Design WPBookit allows SQL Injection.This issue affects WPBookit: from n/a through 1.6.0.
0
Attacker Value
Unknown
CVE-2024-54279
Disclosure Date: December 16, 2024 (last updated December 18, 2024)
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in WPNERD WP-NERD Toolkit.This issue affects WP-NERD Toolkit: from n/a through 1.1.
0
Attacker Value
Unknown
CVE-2024-7701
Disclosure Date: December 15, 2024 (last updated December 18, 2024)
Use of Password Hash With Insufficient Computational Effort vulnerability in percona percona-toolkit allows Encryption Brute Forcing.This issue affects percona-toolkit: 3.6.0.
0
Attacker Value
Unknown
CVE-2023-41875
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in wpdirectorykit.com WP Directory Kit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Directory Kit: from n/a through 1.2.6.
0
Attacker Value
Unknown
CVE-2023-41688
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Mad Fish Digital Bulk NoIndex & NoFollow Toolkit allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Bulk NoIndex & NoFollow Toolkit: from n/a through 1.5.
0
Attacker Value
Unknown
CVE-2023-34019
Disclosure Date: December 13, 2024 (last updated December 18, 2024)
Missing Authorization vulnerability in Uncanny Owl Uncanny Toolkit for LearnDash allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Uncanny Toolkit for LearnDash: from n/a through 3.6.4.3.
0
Attacker Value
Unknown
CVE-2024-54260
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BlazeThemes News Kit Elementor Addons allows Stored XSS.This issue affects News Kit Elementor Addons: from n/a through 1.2.2.
0
Attacker Value
Unknown
CVE-2023-50884
Disclosure Date: December 09, 2024 (last updated December 21, 2024)
Missing Authorization vulnerability in LA-Studio LA-Studio Element Kit for Elementor allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LA-Studio Element Kit for Elementor: from n/a through 1.1.5.
0
Attacker Value
Unknown
CVE-2024-53811
Disclosure Date: December 06, 2024 (last updated December 21, 2024)
Unrestricted Upload of File with Dangerous Type vulnerability in POSIMYTH WDesignkit allows Upload a Web Shell to a Web Server.This issue affects WDesignkit: from n/a through 1.0.40.
0