| CVE-2024-43307 | WordPress Structured Content (JSON-LD) #wpsc plugin <= 1.6.2 - Cross Site Scripting (XSS) vulnerability | Gordon Böhme, Antonio Leutsch | Structured Content | Medium | 6.5 | 2024-08-18 14:20:10 | Deep Dive |
| CVE-2024-7703 | ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup <= 4.0.37 - Authenticated (Subscriber+) Stored Cross-Site Scripting via SVG File Upload | reputeinfosystems | ARMember – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | Medium | 6.4 | 2024-08-17 11:15:02 | Deep Dive |
| CVE-2024-33005 | Missing Authorization check in SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server | SAP_SE | SAP NetWeaver Application Server (ABAP and Java),SAP Web Dispatcher and SAP Content Server | Medium | 6.3 | 2024-08-13 03:47:45 | Deep Dive |
| CVE-2024-2090 | Remote Content Shortcode <= 1.5 - Authenticated (Contributor+) Server-Side Request Forgery | doublesharp | Remote Content Shortcode | Medium | 6.4 | 2024-08-01 04:29:44 | Deep Dive |
| CVE-2024-5969 | AIomatic - Automatic AI Content Writer <= 2.0.5 - Unauthenticated Arbitrary Email Sending | CodeRevolution | Aiomatic - Automatic AI Content Writer & Editor, GPT-3 & GPT-4, ChatGPT ChatBot & AI Toolkit | Medium | 5.8 | 2024-07-27 07:33:47 | Deep Dive |
| CVE-2024-38723 | WordPress Get Use APIs – JSON Content Importer plugin <= 1.5.6 - Server Side Request Forgery (SSRF) vulnerability | Bernhard Kux | JSON Content Importer | Medium | 6.4 | 2024-07-22 10:24:18 | Deep Dive |
| CVE-2024-37465 | WordPress AI Power: Complete AI Pack – Powered by GPT-4 plugin <= 1.8.66 - Cross Site Scripting (XSS) vulnerability | Senol Sahin | GPT3 AI Content Writer | Medium | 6.5 | 2024-07-21 21:24:36 | Deep Dive |
| CVE-2024-38673 | WordPress Multisite Content Copier/Updater plugin <= 1.5.0 - Reflected Cross Site Scripting (XSS) vulnerability | Obtain Infotech | Multisite Content Copier/Updater | High | 7.1 | 2024-07-20 07:55:24 | Deep Dive |
| CVE-2024-5630 | Insert or Embed Articulate Content into WordPress < 4.3000000024 - Author+ Arbitrary File Upload | Unknown | Insert or Embed Articulate Content into WordPress | 中危 | - | 2024-07-15 06:00:02 | Deep Dive |
| CVE-2024-5713 | if-so < 1.8.0.4 - Reflected XSS | Unknown | If-So Dynamic Content Personalization | - | - | 2024-07-13 06:00:13 | Deep Dive |
| CVE-2024-6070 | if-so < 1.8.0.4 - Admin+ Stored XSS | Unknown | If-So Dynamic Content Personalization | - | - | 2024-07-13 06:00:13 | Deep Dive |
| CVE-2024-2430 | Website Content in Page or Post < 2024.04.09 - Contributor+ Stored Cross-Site Scripting | Unknown | Website Content in Page or Post | 中危 | - | 2024-07-12 06:00:05 | Deep Dive |
| CVE-2024-6138 | Secure Copy Content Protection < 4.0.9 - Admin+ Stored XSS | Unknown | Secure Copy Content Protection and Content Locking | - | - | 2024-07-11 06:00:05 | Deep Dive |
| CVE-2024-6069 | Pie Register - Basic <= 3.8.3.4 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Installation | genetechproducts | Pie Register – User Registration, Profiles & Content Restriction | High | 8.8 | 2024-07-09 08:33:11 | Deep Dive |
| CVE-2024-3111 | H5P < 1.15.8 - Contributor+ Stored XSS | Unknown | Interactive Content | - | - | 2024-06-27 06:00:03 | Deep Dive |
| CVE-2024-5596 | ARMember Premium <= 6.7 - Cross-Site Request Forgery via multiple functions | armember | ARMember Premium – Membership Plugin, Content Restriction, Member Levels, User Profile & User signup | Medium | 6.3 | 2024-06-22 05:47:56 | Deep Dive |
| CVE-2024-1407 | Paid Memberships Pro <= 2.12.10 - Cross-Site Request Forgery to Membership Modification | strangerstudios | Paid Memberships Pro – Content Restriction, User Registration, & Paid Subscriptions | Medium | 5.4 | 2024-06-19 06:55:47 | Deep Dive |
| CVE-2023-37394 | WordPress WP Dummy Content Generator plugin <= 2.3.0 - Broken Access Control vulnerability | Deepak anand | WP Dummy Content Generator | Medium | 5.3 | 2024-06-13 23:44:18 | Deep Dive |
| CVE-2024-34820 | WordPress If-So Dynamic Content Personalization plugin <= 1.7.1 - Broken Access Control vulnerability | If So Plugin | If-So Dynamic Content Personalization | Medium | 6.5 | 2024-06-11 14:57:17 | Deep Dive |
| CVE-2024-35716 | WordPress Copymatic plugin <= 1.9 - Broken Access Control vulnerability | Copymatic | Copymatic – AI Content Writer & Generator | Medium | 6.5 | 2024-06-11 09:19:38 | Deep Dive |