| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-1214 | Easy Social Feed <= 6.5.4 - Cross-Site Request Forgery | sjaved | Easy Social Feed – Social Photos Gallery and Post Feed for WordPress | Medium | 4.3 | 2024-03-12 23:33:51 | Deep Dive |
| CVE-2024-1278 | Easy Social Feed – Social Photos Gallery – Post Feed – Like Box <= 6.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | sjaved | Easy Social Feed – Social Photos Gallery and Post Feed for WordPress | Medium | 6.4 | 2024-03-12 23:33:51 | Deep Dive |
| CVE-2024-1213 | Easy Social Feed <= 6.5.4 - Cross-Site Request Forgery | sjaved | Easy Social Feed – Social Photos Gallery and Post Feed for WordPress | Medium | 5.4 | 2024-03-12 23:33:50 | Deep Dive |
| CVE-2024-0386 | weForms <= 1.6.21 - Unauthenticated Stored Cross-Site Scripting via Referer | boldgrid | weForms – Easy Drag & Drop Contact Form Builder For WordPress | High | 7.2 | 2024-03-12 21:34:34 | Deep Dive |
| CVE-2024-0698 | Easy!Appointments <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting | alextselegidis | Easy!Appointments | Medium | 6.4 | 2024-03-05 01:56:00 | Deep Dive |
| CVE-2023-51683 | WordPress Easy PayPal Buy Now Button Plugin <= 1.8.1 is vulnerable to Cross Site Request Forgery (CSRF) | Scott Paterson | Easy PayPal & Stripe Buy Now Button | Medium | 5.4 | 2024-02-28 16:45:07 | Deep Dive |
| CVE-2024-1719 | Easy PayPal & Stripe Buy Now Button <= 1.8.3 & Contact Form 7 – PayPal & Stripe Add-on <= 2.1 - Cross-Site Request Forgery to Settings Update | scottpaterson | Easy PayPal & Stripe Buy Now Button | Medium | 4.3 | 2024-02-28 09:33:35 | Deep Dive |
| CVE-2024-25925 | WordPress WooCommerce Easy Checkout Field Editor, Fees & Discounts Plugin <= 3.5.12 is vulnerable to Arbitrary File Upload | SYSBASICS | WooCommerce Easy Checkout Field Editor, Fees & Discounts | Critical | 10.0 | 2024-02-26 15:09:16 | Deep Dive |
| CVE-2024-0659 | Easy Digital Downloads <= 3.2.6 - Authenticated(Shop Manager+) Stored Cross-Site Scripting via variable pricing options | smub | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | Medium | 5.5 | 2024-02-05 21:21:36 | Deep Dive |
| CVE-2024-24848 | WordPress PT Sign Ups Plugin <= 1.0.4 is vulnerable to Cross Site Scripting (XSS) | MJS Software | PT Sign Ups – Beautiful volunteer sign ups and management made easy | High | 7.1 | 2024-02-05 06:11:27 | Deep Dive |
| CVE-2024-1187 | Munsoft Easy Outlook Express Recovery Registration Key denial of service | Munsoft | Easy Outlook Express Recovery | Low | 3.3 | 2024-02-02 17:31:04 | Deep Dive |
| CVE-2024-1186 | Munsoft Easy Archive Recovery Registration Key denial of service | Munsoft | Easy Archive Recovery | Low | 3.3 | 2024-02-02 17:00:07 | Deep Dive |
| CVE-2024-23895 | Cross-Site Scripting (XSS) vulnerability in Cups Easy | Cups Easy | Cups Easy (Purchase & Inventory) | High | 8.2 | 2024-02-02 09:18:59 | Deep Dive |
| CVE-2023-51689 | WordPress Easy Video Player Plugin <= 1.2.2.10 is vulnerable to Cross Site Scripting (XSS) | naa986 | Easy Video Player | Medium | 6.5 | 2024-02-01 10:39:39 | Deep Dive |
| CVE-2023-51684 | WordPress Easy Digital Downloads Plugin <= 3.2.5 is vulnerable to Cross Site Scripting (XSS) | Easy Digital Downloads | Easy Digital Downloads – Sell Digital Files (eCommerce Store & Payments Made Easy) | Medium | 6.5 | 2024-02-01 10:34:37 | Deep Dive |
| CVE-2023-7089 | Easy SVG Allow <= 1.0 - Author+ Stored XSS via SVG | Unknown | Easy SVG Allow | 中危 | - | 2024-01-29 14:44:25 | Deep Dive |
| CVE-2024-23896 | Cross-Site Scripting (XSS) vulnerability in Cups Easy | Cups Easy | Cups Easy (Purchase & Inventory) | High | 8.2 | 2024-01-26 10:18:49 | Deep Dive |
| CVE-2024-23894 | Cross-Site Scripting (XSS) vulnerability in Cups Easy | Cups Easy | Cups Easy (Purchase & Inventory) | High | 8.2 | 2024-01-26 10:18:04 | Deep Dive |
| CVE-2024-23893 | Cross-Site Scripting (XSS) vulnerability in Cups Easy | Cups Easy | Cups Easy (Purchase & Inventory) | High | 8.2 | 2024-01-26 10:17:46 | Deep Dive |
| CVE-2024-23892 | Cross-Site Scripting (XSS) vulnerability in Cups Easy | Cups Easy | Cups Easy (Purchase & Inventory) | High | 8.2 | 2024-01-26 10:17:19 | Deep Dive |