| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-52351 | WordPress BU Slideshow plugin <= 2.3.10 - Cross Site Scripting (XSS) vulnerability | BU Web Team | BU Slideshow | Medium | 6.5 | 2024-11-11 06:41:57 | Deep Dive |
| CVE-2024-51689 | WordPress CF7 WOW Styler plugin <= 1.6.8 - Reflected Cross Site Scripting (XSS) vulnerability | Saleswonder Team: Tobias | CF7 WOW Styler | High | 7.1 | 2024-11-09 12:53:18 | Deep Dive |
| CVE-2024-51763 | WordPress Team Showcase and Slider plugin <= 1.3 - Reflected Cross Site Scripting (XSS) vulnerability | biplob018 | Team Showcase and Slider – Team Members Builder | High | 7.1 | 2024-11-09 09:27:37 | Deep Dive |
| CVE-2024-51579 | WordPress 5 Stars Rating Funnel plugin <=1.4.01 - SQL Injection vulnerability | Saleswonder Team: Tobias | 5 Stars Rating Funnel | High | 8.5 | 2024-11-09 09:04:47 | Deep Dive |
| CVE-2024-51784 | WordPress FriendStore for WooCommerce plugin <= 1.4.2 - Reflected Cross Site Scripting (XSS) vulnerability | VietFriend team | FriendStore for WooCommerce | High | 7.1 | 2024-11-09 08:28:59 | Deep Dive |
| CVE-2024-37095 | WordPress Envira Photo Gallery plugin <= 1.8.7.3 - CSRF leading to notice dismissal vulnerability | Envira Gallery Team | Envira Photo Gallery | Medium | 4.3 | 2024-11-01 14:18:39 | Deep Dive |
| CVE-2024-37096 | WordPress Popup box plugin <= 4.5.1 - Broken Access Control vulnerability | Popup Box Team | Popup box | Medium | 4.3 | 2024-11-01 14:18:38 | Deep Dive |
| CVE-2024-37218 | WordPress Page Builder Sandwich <= 5.1.0 - Broken Access Control vulnerability | WordPress Page Builder Sandwich Team | Page Builder Sandwich – Front-End Page Builder | Medium | 4.3 | 2024-11-01 14:18:32 | Deep Dive |
| CVE-2024-37506 | WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability | Charitable Donations & Fundraising Team | Charitable | Medium | 5.3 | 2024-11-01 14:18:14 | Deep Dive |
| CVE-2024-37510 | WordPress Donation Forms by Charitable plugin <= 1.8.1.7 - Broken Access Control vulnerability | Charitable Donations & Fundraising Team | Charitable | Medium | 6.5 | 2024-11-01 14:18:13 | Deep Dive |
| CVE-2024-38792 | WordPress ConveyThis Translate plugin <= 234 - Non-arbitrary Options Update vulnerability | ConveyThis Translate Team | Language Translate Widget for WordPress – ConveyThis | Medium | 5.3 | 2024-11-01 14:17:56 | Deep Dive |
| CVE-2024-43212 | WordPress WpTravelly plugin <= 1.7.7 - Broken Access Control vulnerability | MagePeople Team | WpTravelly | High | 7.5 | 2024-11-01 14:17:40 | Deep Dive |
| CVE-2024-43925 | WordPress Envira Gallery Lite plugin <= 1.8.14 - Broken Access Control vulnerability | Envira Gallery Team | Envira Photo Gallery | Medium | 4.3 | 2024-11-01 14:17:20 | Deep Dive |
| CVE-2024-10223 | HT Team Member <= 1.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via htteamember Shortcode | htplugins | WP Team – WordPress Team Member Plugin | Medium | 6.4 | 2024-10-30 06:43:36 | Deep Dive |
| CVE-2024-9930 | Extensions by HocWP Team <= 0.2.3.2 - Authentication Bypass | skylarkcob | Extensions by HocWP Team | Critical | 9.8 | 2024-10-26 01:58:38 | Deep Dive |
| CVE-2024-9947 | ProfilePress - Pro <= 4.11.1 - Authentication Bypass via WordPress.com OAuth provider | ProfilePress Team | ProfilePress Pro | High | 8.1 | 2024-10-23 06:45:06 | Deep Dive |
| CVE-2024-49281 | WordPress Click to Chat – WP Support All-in-One Floating Widget plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability | Ninja Team | Click to Chat – WP Support All-in-One Floating Widget | Medium | 6.5 | 2024-10-17 19:15:28 | Deep Dive |
| CVE-2024-47351 | WordPress MaxSlider plugin <= 1.2.3 - Local File Inclusion vulnerability | The CSSIgniter Team | MaxSlider | High | 7.5 | 2024-10-16 13:36:37 | Deep Dive |
| CVE-2022-4974 | Freemius SDK <= 2.4.2 - Missing Authorization Checks | dashlabsltd | YASR – Yet Another Star Rating Plugin for WordPress | Medium | 6.3 | 2024-10-16 06:43:30 | Deep Dive |
| CVE-2024-9923 | TEAMPLUS TECHNOLOGY Team+ - Arbitrary File Move through Path Traversal | teamplus technology | team+ | Medium | 4.9 | 2024-10-14 03:17:07 | Deep Dive |