| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-47331 | WordPress Multi Step for Contact Form plugin <= 2.7.7 - Unauthenticated SQL Injection vulnerability | Ninja Team | Multi Step for Contact Form | Critical | 9.3 | 2024-10-11 18:20:06 | Deep Dive |
| CVE-2024-43972 | WordPress Page Builder: Pagelayer – Drag and Drop website builder plugin <= 1.8.7 - Cross Site Scripting (XSS) vulnerability | Pagelayer Team | PageLayer | Medium | 5.9 | 2024-09-17 23:30:56 | Deep Dive |
| CVE-2024-44002 | WordPress Team Showcase plugin <= 1.22.25 - Reflected Cross Site Scripting (XSS) vulnerability | PickPlugins | Team Showcase | High | 7.1 | 2024-09-17 23:12:03 | Deep Dive |
| CVE-2024-43985 | WordPress Bus Ticket Booking with Seat Reservation plugin <= 5.3.5 - Cross Site Scripting (XSS) vulnerability | MagePeople Team | Bus Ticket Booking with Seat Reservation | Medium | 5.9 | 2024-09-17 22:41:39 | Deep Dive |
| CVE-2024-43926 | WordPress Beaver Builder plugin <= 2.8.3.2 - Reflected Cross Site Scripting (XSS) vulnerability | The Beaver Builder Team | Beaver Builder | High | 7.1 | 2024-08-29 18:10:31 | Deep Dive |
| CVE-2024-43986 | WordPress E-cab taxi booking manager plugin <=1.0.9 - Cross Site Scripting (XSS) vulnerability | MagePeople Team | Taxi Booking Manager for WooCommerce | Medium | 5.9 | 2024-08-29 09:00:17 | Deep Dive |
| CVE-2024-43289 | WordPress wpForo Forum plugin <= 2.3.4 - Unauthenticated Sensitive Data Exposure vulnerability | gVectors Team | wpForo Forum | High | 7.5 | 2024-08-26 16:06:02 | Deep Dive |
| CVE-2024-43317 | WordPress RegistrationMagic plugin <= 6.0.1.0 - Cross Site Scripting (XSS) vulnerability | Metagauss User Registration Team | RegistrationMagic | Medium | 4.3 | 2024-08-19 19:22:53 | Deep Dive |
| CVE-2024-43288 | WordPress wpForo Forum plugin <= 2.3.4 - Insecure Direct Object References (IDOR) vulnerability | gVectors Team | wpForo Forum | Medium | 4.3 | 2024-08-18 21:33:37 | Deep Dive |
| CVE-2024-43321 | WordPress Team Showcase plugin <= 1.22.23 - Cross Site Scripting (XSS) vulnerability | PickPlugins | Team Showcase | Medium | 6.5 | 2024-08-18 14:13:55 | Deep Dive |
| CVE-2024-43138 | WordPress Event Manager and Tickets Selling Plugin for WooCommerce plugin <= 4.2.1 - Local File Inclusion vulnerability | MagePeople Team | Event Manager for WooCommerce | Medium | 6.5 | 2024-08-13 11:35:21 | Deep Dive |
| CVE-2024-35775 | WordPress Slider by Soliloquy plugin <= 2.7.6 - Broken Access Control to XSS vulnerability | Soliloquy Team | Slider by Soliloquy | Medium | 5.9 | 2024-08-12 22:55:15 | Deep Dive |
| CVE-2024-43137 | WordPress WappPress Basic plugin <= 6.0.4 - Cross Site Scripting (XSS) vulnerability | WappPress Team | WappPress | Medium | 5.9 | 2024-08-12 22:26:10 | Deep Dive |
| CVE-2024-43220 | WordPress Form Maker by 10Web plugin <= 1.15.26 - Reflected Cross Site Scripting (XSS) vulnerability | 10Web Form Builder Team | Form Maker by 10Web | High | 7.1 | 2024-08-12 21:22:38 | Deep Dive |
| CVE-2024-7693 | Team Johnlong software Raiden MAILD Remote Management System - Arbitrary File Reading through Path Traversal | Team Johnlong software | Raiden MAILD Remote Management System | High | 7.5 | 2024-08-12 02:44:36 | Deep Dive |
| CVE-2024-42366 | VR Overlay RCE | vrcx-team | VRCX | Critical | 9.0 | 2024-08-08 16:51:07 | Deep Dive |
| CVE-2024-38746 | WordPress MakeStories (for Google Web Stories) plugin <= 3.0.3 - Arbitrary File Download and SSRF vulnerability | MakeStories Team | MakeStories (for Google Web Stories) | High | 7.1 | 2024-08-01 21:02:30 | Deep Dive |
| CVE-2024-37211 | WordPress AliExpress Dropshipping with AliNext Lite plugin <= 3.3.5 - Reflected Cross Site Scripting (XSS) vulnerability | Ali2Woo Team | Ali2Woo Lite | High | 7.1 | 2024-07-22 09:30:08 | Deep Dive |
| CVE-2024-37244 | WordPress Ninja Beaver Add-ons for Beaver Builder plugin <= 2.4.5 - Cross Site Scripting (XSS) vulnerability | Ninja Team | Ninja Beaver Add-ons for Beaver Builder | Medium | 6.5 | 2024-07-22 09:13:18 | Deep Dive |
| CVE-2024-37492 | WordPress Gutenberg plugin <= 18.6.0 - Cross Site Scripting (XSS) vulnerability | Gutenberg Team | Gutenberg | Medium | 6.5 | 2024-07-21 07:28:00 | Deep Dive |