| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-10852 | Buy one click WooCommerce <= 2.2.9 - Missing Authorization to Authenticated (Subscriber+) Settings Export | northmule | Buy one click WooCommerce | Medium | 4.3 | 2024-11-13 02:02:29 | Deep Dive |
| CVE-2024-51575 | WordPress Extender All In One For Elementor plugin <= 1.0.3 - Stored Cross Site Scripting (XSS) vulnerability | Md. Abdullah Al Masum | Extender All In One For Elementor | Medium | 6.5 | 2024-11-11 05:45:26 | Deep Dive |
| CVE-2024-6626 | EleForms – All In One Form Integration including DB for Elementor <= 2.9.9.9 - Missing Authorization | cscode | EleForms – All In One Form Integration including DB for Elementor | Medium | 5.3 | 2024-11-06 06:43:32 | Deep Dive |
| CVE-2024-37444 | WordPress Defender plugin <= 4.7.1 - Broken Access Control vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Defender Security | Medium | 5.3 | 2024-11-01 14:18:21 | Deep Dive |
| CVE-2024-37505 | WordPress Business One Page theme <= 1.2.9 - Broken Access Control on Notice Dismissal vulnerability | Rara Themes | Business One Page | Medium | 4.3 | 2024-11-01 14:18:14 | Deep Dive |
| CVE-2024-43118 | WordPress Hummingbird plugin <= 3.9.1 - Broken Access Control vulnerability | WPMU DEV - Your All-in-One WordPress Platform | Hummingbird | Medium | 4.3 | 2024-11-01 14:17:50 | Deep Dive |
| CVE-2024-9162 | All-in-One WP Migration and Backup <= 7.86 - Authenticated (Administrator+) Arbitrary PHP Code Injection | servmask | All-in-One WP Migration and Backup | High | 7.2 | 2024-10-28 05:32:25 | Deep Dive |
| CVE-2024-45335 | Trend Micro Antivirus One 安全漏洞 | Trend Micro, Inc. | Trend Micro Antivirus One | High | 8.4 | 2024-10-22 18:27:58 | Deep Dive |
| CVE-2024-45334 | Trend Micro Antivirus One 安全漏洞 | Trend Micro, Inc. | Trend Micro Antivirus One | High | 7.8 | 2024-10-22 18:27:11 | Deep Dive |
| CVE-2024-39753 | Trend Micro Apex One和Trend Micro Apex One as a Service 安全漏洞 | Trend Micro, Inc. | Trend Micro Apex One | High | 7.5 | 2024-10-22 18:26:23 | Deep Dive |
| CVE-2024-8852 | All-in-One WP Migration and Backup <= 7.86 - Unauthenticated Information Disclosure via Error Logs | servmask | All-in-One WP Migration and Backup | Medium | 5.3 | 2024-10-22 05:33:49 | Deep Dive |
| CVE-2024-49323 | WordPress All in One Slider plugin <= 1.1 - Reflected Cross Site Scripting (XSS) vulnerability | Shahriar Alam | All in One Slider | High | 7.1 | 2024-10-20 07:53:29 | Deep Dive |
| CVE-2024-10055 | Click to Chat – WP Support All-in-One Floating Widget <= 2.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting via wpsaio_snapchat Shortcode | ninjateam | WP Click to Chat – Email, Live Chat, Call & Book Now Buttons | Medium | 6.4 | 2024-10-18 07:35:26 | Deep Dive |
| CVE-2024-49281 | WordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability | Ninja Team | Click to Chat – WP Support All-in-One Floating Widget | Medium | 6.5 | 2024-10-17 19:15:28 | Deep Dive |
| CVE-2019-25217 | SiteGround Optimizer <= 5.0.12 - Missing Authorization | siteground | Speed Optimizer – The All-In-One Performance-Boosting Plugin | Critical | 9.8 | 2024-10-16 06:43:34 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-9649 | WP ULike <= 4.7.4 - Cross-Site Request Forgery to Statistic Deletion | alimir | WP ULike – Like & Dislike Buttons for Engagement and Feedback | Medium | 4.3 | 2024-10-16 02:05:04 | Deep Dive |
| CVE-2024-9538 | ShopLentor <= 2.9.8 - Authenticated (Contributor+) Sensitive Information Exposure via WL: FAQ Widget Elementor Template | devitemsllc | ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin | Medium | 4.3 | 2024-10-11 11:01:55 | Deep Dive |
| CVE-2024-9071 | Easy Demo Importer – A Modern One-Click Demo Import Solution <= 1.1.2 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | sigmadevs | Easy Demo Importer – A Modern One-Click Demo Import Solution | Medium | 6.4 | 2024-10-04 09:30:41 | Deep Dive |
| CVE-2024-8733 | HP One Agent Software – Potential Privilege Escalation | HP, Inc. | HP One Agent Software | High | 8.0 | 2024-10-02 19:12:41 | Deep Dive |