| CVE-2024-10785 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.3 - Authenticated (Contributor+) Stored Cross-Site Scripting | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-11-21 04:24:25 | Deep Dive |
| CVE-2024-11360 | Page Parts <= 1.4.3 - Reflected Cross-Site Scripting | husobj | Page Parts | Medium | 6.1 | 2024-11-21 02:06:38 | Deep Dive |
| CVE-2024-52447 | WordPress Contact Page With Google Map plugin <= 1.6.1 - Arbitrary File Deletion vulnerability | corporatezen222 | Contact Page With Google Map | High | 8.6 | 2024-11-20 11:07:30 | Deep Dive |
| CVE-2024-10365 | The Plus Addons for Elementor – Elementor Addons, Page Templates, Widgets, Mega Menu, WooCommerce <= 6.0.3 - Authenticated (Contributor+) Sensitive Information Exposure via Elementor Templates | posimyththemes | The Plus Addons for Elementor – Addons for Elementor, Page Templates, Widgets, Mega Menu, WooCommerce | Medium | 4.3 | 2024-11-20 06:42:57 | Deep Dive |
| CVE-2024-51633 | WordPress Simple Page Specific Sidebars plugin <= 2.14.1 - CSRF to Stored Cross Site Scripting (XSS) vulnerability | ivycat | Simple Page Specific Sidebars | High | 7.1 | 2024-11-19 16:32:30 | Deep Dive |
| CVE-2024-51917 | WordPress Multiple Votes in one page plugin <= 1.0.4 - Cross Site Scripting (XSS) vulnerability | lequanghuylc | Multiple Votes in one page | Medium | 6.5 | 2024-11-19 16:30:59 | Deep Dive |
| CVE-2024-50417 | WordPress Bold Page Builder plugin <= 5.1.3 - Broken Access Control vulnerability | boldthemes | Bold Page Builder | Medium | 4.3 | 2024-11-19 16:30:39 | Deep Dive |
| CVE-2024-9935 | PDF Generator Addon for Elementor Page Builder <= 2.0.0 - Unauthenticated Arbitrary File Download | redefiningtheweb | PDF Generator for WordPress Elementor | High | 7.5 | 2024-11-16 03:20:45 | Deep Dive |
| CVE-2024-10685 | Contact Form 7 Redirect & Thank You Page <= 1.0.6 - Reflected Cross-Site Scripting | scottpaterson | Business Essentials for Contact Form 7 | Medium | 6.1 | 2024-11-12 03:24:59 | Deep Dive |
| CVE-2024-10672 | Multiple Page Generator Plugin – MPG <= 4.0.2 - Authenticated (Editor+) Directory Traversal to Limited File Deletion | themeisle | Multiple Page Generator Plugin – MPG | Low | 2.7 | 2024-11-12 03:24:58 | Deep Dive |
| CVE-2024-51585 | WordPress Sales Page Addon plugin <= 1.4.5 - Stored Cross Site Scripting (XSS) vulnerability | nicheaddons | Sales Page Addon – Elementor & Beaver Builder | Medium | 6.5 | 2024-11-09 14:59:25 | Deep Dive |
| CVE-2024-9226 | Landing Page Cat – Coming Soon Page, Maintenance Page & Squeeze Pages <= 1.7.6 - Reflected Cross-Site Scripting | fatcatapps | Landing Page Cat – Coming Soon & Maintenance Pages | Medium | 6.1 | 2024-11-09 03:18:13 | Deep Dive |
| CVE-2024-37218 | WordPress Page Builder Sandwich <= 5.1.0 - Broken Access Control vulnerability | WordPress Page Builder Sandwich Team | Page Builder Sandwich – Front-End Page Builder | Medium | 4.3 | 2024-11-01 14:18:32 | Deep Dive |
| CVE-2024-37505 | WordPress Business One Page theme <= 1.2.9 - Broken Access Control on Notice Dismissal vulnerability | Rara Themes | Business One Page | Medium | 4.3 | 2024-11-01 14:18:14 | Deep Dive |
| CVE-2024-43314 | WordPress Asset CleanUp: Page Speed Booster plugin <= 1.3.9.3 - Broken Access Control vulnerability | Gabe Livan | Asset CleanUp: Page Speed Booster | Medium | 4.3 | 2024-11-01 14:17:26 | Deep Dive |
| CVE-2024-43932 | WordPress The Plus Addons for Elementor plugin <= 5.6.2 - Broken Access Control vulnerability | POSIMYTH | The Plus Addons for Elementor Page Builder Lite | Medium | 6.5 | 2024-11-01 14:17:18 | Deep Dive |
| CVE-2024-10367 | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE <= 3.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via SVG File Upload | themeisle | Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE | Medium | 6.4 | 2024-11-01 11:01:56 | Deep Dive |
| CVE-2024-9655 | Gutenberg Blocks with AI by Kadence WP – Page Builder Features <= 3.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Icon Widget | stellarwp | Kadence Blocks — Page Builder Toolkit for Gutenberg Editor | Medium | 6.4 | 2024-11-01 07:33:30 | Deep Dive |
| CVE-2024-7424 | Multiple Page Generator Plugin – MPG <= 4.0.1 - Missing Authorization | themeisle | Multiple Page Generator Plugin – MPG | Medium | 5.4 | 2024-11-01 07:33:30 | Deep Dive |
| CVE-2024-9505 | Beaver Builder – WordPress Page Builder <= 2.8.4.2 - Authenticated (Contributor+) Stored DOM-Based Cross-Site Scripting via Button Widget | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | Medium | 6.4 | 2024-10-29 13:53:56 | Deep Dive |