| CVE-2024-53749 | WordPress Post Carousel Slider for Elementor plugin <= 1.5.0 - Cross Site Scripting (XSS) vulnerability | Plugin Devs | Post Carousel Slider for Elementor | Medium | 6.5 | 2024-12-01 21:21:51 | Deep Dive |
| CVE-2024-11601 | Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) <= 2.6.1 - Cross-Site Request Forgery to Limited Arbitrary Options Update | wowdevs | Sky Addons – Elementor Addons with Widgets & Templates | High | 8.1 | 2024-11-22 05:33:41 | Deep Dive |
| CVE-2024-11104 | Sky Addons for Elementor (Free Templates Library, Live Copy, Animations, Post Grid, Post Carousel, Particles, Sliders, Chart, Blogs) <= 2.6.2 - Missing Authorization to Authenticated (Subscriber+) Limited Arbitrary Options Update | wowdevs | Sky Addons – Elementor Addons with Widgets & Templates | High | 8.1 | 2024-11-22 05:33:40 | Deep Dive |
| CVE-2024-9542 | Sky Addons for Elementor <= 2.6.1 - Authenticated (Contributor+) Sensitive Information Exposure via Content Switcher Widget Elementor Template | wowdevs | Sky Addons – Elementor Addons with Widgets & Templates | Medium | 4.3 | 2024-11-21 11:02:20 | Deep Dive |
| CVE-2024-52451 | WordPress Post Ideas plugin <= 2 - CSRF to SQL Injection vulnerability | aaronrobbins | Post Ideas | High | 8.2 | 2024-11-20 11:54:29 | Deep Dive |
| CVE-2024-51650 | WordPress Random Featured Post plugin <= 1.1.3 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | scottmydollarplancom | Random Featured Post | High | 7.1 | 2024-11-19 16:32:22 | Deep Dive |
| CVE-2024-51852 | WordPress Dynamic Post Grid Elementor Addon plugin <= 1.0.6 - Cross Site Scripting (XSS) vulnerability | Maidul | Dynamic Post Grid Elementor Addon | Medium | 6.5 | 2024-11-19 16:31:34 | Deep Dive |
| CVE-2024-51893 | WordPress Postify: Post Layout For Elementor plugin <= 1.0.1 - Cross Site Scripting (XSS) vulnerability | FixoLab | Postify: Post Layout For Elementor | Medium | 6.5 | 2024-11-19 16:31:12 | Deep Dive |
| CVE-2024-51928 | WordPress Blocks Post Grid plugin <= 1.0.3 - Cross Site Scripting (XSS) vulnerability | Jakir Hasan | Blocks Post Grid | Medium | 6.5 | 2024-11-19 16:30:54 | Deep Dive |
| CVE-2024-52436 | WordPress Post SMTP plugin <= 2.9.9 - SQL Injection vulnerability | Saad Iqbal | Post SMTP | High | 7.6 | 2024-11-18 14:30:21 | Deep Dive |
| CVE-2024-10728 | PostX <= 4.1.16 - Missing Authorization to Arbitrary Plugin Installation/Activation | wpxpo | Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX | High | 8.8 | 2024-11-16 04:29:15 | Deep Dive |
| CVE-2024-51701 | WordPress MG Post Contributors plugin <= 1.3. - Reflected Cross Site Scripting (XSS) vulnerability | Mahesh Waghmare | MG Post Contributors | High | 7.1 | 2024-11-09 12:35:30 | Deep Dive |
| CVE-2024-51783 | WordPress Forms: 3rd-Party Post Again plugin <= 0.3 - Reflected Cross Site Scripting (XSS) vulnerability | zaus | Forms: 3rd-Party Post Again | High | 7.1 | 2024-11-09 08:29:59 | Deep Dive |
| CVE-2024-10186 | Event Post <= 5.9.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via events_cal Shortcode | bastho | Event post | Medium | 6.4 | 2024-11-06 12:43:14 | Deep Dive |
| CVE-2024-9689 | Post From Frontend <= 1.0.0 - Post Deletion via CSRF | Unknown | Post From Frontend | - | - | 2024-11-05 06:00:08 | Deep Dive |
| CVE-2024-51683 | WordPress Custom post type templates for Elementor plugin <= 1.10.1 - Stored Cross Site Scripting (XSS) vulnerability | Michael | Custom post type templates for Elementor | Medium | 6.5 | 2024-11-04 14:11:51 | Deep Dive |
| CVE-2024-50523 | WordPress All Post Contact Form plugin <= 1.8.2 - Arbitrary File Upload vulnerability | RainbowLink Inc. | All Post Contact Form | Critical | 10.0 | 2024-11-04 13:46:00 | Deep Dive |
| CVE-2024-37481 | WordPress The Post Grid plugin <= 7.7.4 - Broken Access Control vulnerability | RadiusTheme | The Post Grid | Medium | 6.5 | 2024-11-01 14:18:16 | Deep Dive |
| CVE-2024-37482 | WordPress The Post Grid plugin <= 7.7.4 - Broken Access Control vulnerability | RadiusTheme | The Post Grid | Medium | 4.3 | 2024-11-01 14:18:16 | Deep Dive |
| CVE-2024-37483 | WordPress The Post Grid plugin <= 7.7.4 - Broken Access Control vulnerability | RadiusTheme | The Post Grid | Medium | 5.4 | 2024-11-01 14:18:15 | Deep Dive |